Novidade Exploit Kit Actively Targeting SOHO and Home Routers
#1
Quote:Trend Micro's security researchers discovered multiple campaigns during September and October that wielded the Novidade exploit kit capable of changing Domain Name System (DNS) settings on home and SOHO routers with the help of cross-site request forgery (CSRF) attacks.

The attackers employ this the exploit kit to attack victims using both desktop and mobile devices, with the vast majority of malware campaigns that utilized it targeting banking credentials of Brazillian customers.

Novidade can exfiltrate banking info from its targets by changing vulnerable routers' DNS settings to those of maliciously configured servers controlled by its masters, allowing them to carry out pharming attacks on all devices connected to the compromised router.

As discovered by Trend Micro
, the first Novidade samples were unearthed during August 2017, with two separate strains spotted in the wild until now while being used in multiple campaigns.

This leads to the conclusion that the exploit kit has either been sold or shared between multiple threat groups, or that its source code has been inadvertently leaked and modified by other groups to suit their needs and, subsequently, being added to their toolset.

Source: https://news.softpedia.com/news/new-novi...4230.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.208.2004 (already released ...
uBOLite 2026.208.2...harlan4096 — 08:33
Intel 900-series chipset spcs leaked: B9...
Core Ultra 400S an...harlan4096 — 08:32
Default TRIM Windows Setting Is Making Y...
Solid-state drive ...harlan4096 — 08:29
Revo Uninstaller Pro Updates
Revo Uninstaller P...Mohammad.Poorya — 18:44
K-Lite Codec Pack 19.4.5 / 19.4.8 Update
Changes in 19.4.8 ...harlan4096 — 07:29

[-]
Birthdays
Today's Birthdays
avatar (47)hapedDow
avatar (46)komriwat
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>