Trojanized TeamViewer used in government, embassy attacks across Europe
#1
Quote:A new, targeted attack weaponizing TeamViewer has been uncovered which focuses on stealing financial information belonging to governmental and financial targets across Europe and beyond.
 
Researchers from Check Point said on Monday that the campaign is specifically targeting officials in government finance capacities and embassy representatives in Europe, alongside Nepal, Kenya, Liberia, Lebanon, Guyana, and Bermuda.
 
The infection vector begins with a typical phishing email containing a malicious attachment claiming to be a "Top Secret" document from the United States. 
 
The email sent to potential victims contains the subject line "Military Financing Program" and the .XLSM document attached to the message has been crafted with a logo from the US Department of State in a bid to appear legitimate.

If a target downloads and opens the attachment, they are asked to enable macros -- a very common method employed by attackers to gain access to a victim system. Should they do so, two files are extracted -- a legitimate AutoHotkeyU32.exe program and a malicious TeamViewer DLL.

SOURCE: https://www.zdnet.com/article/trojanized...ss-europe/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
YouTube updates Shorts view count metho...
This is a smart and ...Kiran78 — 11:41
Microsoft Edge 135.0.3179.73
Version 135.0.3179...harlan4096 — 06:08
AnyDesk 9.5.1 for Windows
AnyDesk 9.5.1 for ...harlan4096 — 06:07
Messengers 101: safety and privacy advic...
A dozen short and ...harlan4096 — 06:05
Google Docs introduces Audio Overviews t...
Google has announc...harlan4096 — 06:02

[-]
Birthdays
Today's Birthdays
avatar (37)urumahiz
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (45)MeighGoask
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
avatar (42)cdoubapKit
avatar (37)lystraPonia
avatar (30)smith8395john
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (45)Rodneykak
avatar (48)tradeSmode
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>