Trojanized TeamViewer used in government, embassy attacks across Europe
#1
Quote:A new, targeted attack weaponizing TeamViewer has been uncovered which focuses on stealing financial information belonging to governmental and financial targets across Europe and beyond.
 
Researchers from Check Point said on Monday that the campaign is specifically targeting officials in government finance capacities and embassy representatives in Europe, alongside Nepal, Kenya, Liberia, Lebanon, Guyana, and Bermuda.
 
The infection vector begins with a typical phishing email containing a malicious attachment claiming to be a "Top Secret" document from the United States. 
 
The email sent to potential victims contains the subject line "Military Financing Program" and the .XLSM document attached to the message has been crafted with a logo from the US Department of State in a bid to appear legitimate.

If a target downloads and opens the attachment, they are asked to enable macros -- a very common method employed by attackers to gain access to a victim system. Should they do so, two files are extracted -- a legitimate AutoHotkeyU32.exe program and a malicious TeamViewer DLL.

SOURCE: https://www.zdnet.com/article/trojanized...ss-europe/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Trying out EaseUS Video Downloader Pro
This is a very g...masonwright757 — 21:58
XYplorer
XYplorer (64-bit) v2...jAcos — 17:39
RAM Booster for PC
harlan4096 — 10:23
RAM Booster for PC
Hello, Plz Sugges...alina104 — 09:34
Microsoft Retires Standalone SharePoint ...
Microsoft Is Ending...harlan4096 — 08:29

[-]
Birthdays
Today's Birthdays
avatar (48)Michaelecozy
Upcoming Birthdays
avatar (47)hapedDow
avatar (46)komriwat
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)delsreehRob
avatar (44)pyotrded
avatar (41)oecmecodo
avatar (40)ShakitaSmobe
avatar (49)tsorenHievy
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (41)svoyaEnuct
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (41)yposegij
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>