GitHub-Hosted Malware Targets Accountants With Ransomware
#1
Quote:Threat actors ran a malvertising campaign on the Russian Yandex.Direct advertising network starting October 2018 to disseminate a malware cocktail designed to encrypt victims' data and steal cryptocurrency.
 
The hacking group targeted Russian organizations using malicious payloads camouflaged as document templates and hosted on the GitHub code hosting platform, one of the goals being to steal sensitive cryptocurrency-related data.
 
As the ESET Research team detailed in its report, Yandex disabled the malvertising campaign after receiving their alert about malicious ads used to redirect victims to malware-ridden template packs.

ESET Research's analysis further revealed that the targets were lured to the malvertising landing pages after searching for key-phrases similar to "download invoice template," "claim complaint example," or "examples of legal contracts" which indicates that the campaign was targeting corporate entities by attempting to compromise their accountants' computers.

The researchers also found that "the cybercriminals put the malicious files on their GitHub repository only for a limited period of time, probably while the ad campaign was active. Most of the time, the payload on GitHub was an empty zip file or a clean executable."

SOURCE: https://www.bleepingcomputer.com/news/se...ansomware/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 18.8.5 / 18.8.9 Update
Changes in 18.8.9 ...harlan4096 — 07:13
Ubuntu 24.04.2 LTS / 25.04
Ubuntu 24.04.2 LTS...harlan4096 — 07:12
Microsoft Edge 135.0.3179.85
Version 135.0.3179...harlan4096 — 07:10
AnyDesk 7.0.0 for Linux
AnyDesk 7.0.0 for ...harlan4096 — 07:08
Intel releases AI Playground software fo...
Intel is open sour...harlan4096 — 07:07

[-]
Birthdays
Today's Birthdays
avatar (48)oapedDow
avatar (41)Sanchowogy
Upcoming Birthdays
avatar (44)wapedDow
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>