Threat Group Uses CAD Malware to Compromise Energy/Automotive Targets
#1
Quote:Forcepoint's security researchers found traces of a threat group which targets energy and automotive companies using CAD malware via a campaign running since at least 2014.

CAD malware uses maliciously crafted design files which auto-load encrypted scripts designed as run-of-the-mill malware downloaders that drop a wide variety of malicious tools on the infiltrated system.

However, unlike in the case of phishing attacks which use malicious documents attached to email messages, CAD malware campaigns will host the malicious project files either on a private hosting server or a public file sharing service, serving the target with a direct download link.

There are also campaigns which use USB storage drives or CDs/DVDs sent via postal services, exploiting the fact that a lot of enterprises would instead receive this type of documents in physical form rather than downloading them from the web, from a potentially not trustworthy source.

The latest victims compromised by the bad actors behind the CAD malware campaign observed by the ForcePoint researchers were infected using AutoCAD project files that automatically loaded AutoLISP-based scripts upon opening.

"Our telemetry shows the infection extant at least as long ago as late 2014 and, further, that new victims appear to have been infected as recently as mid-2018 with the majority of infected machines appearing in China, India, Turkey, and the UAE," says ForcePoint.

Source: https://news.softpedia.com/news/threat-g...4038.shtml
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, wwd
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Google Chrome 146.0.7680.177/178
Google Chrome 146....harlan4096 — 07:22
F-Secure v26.3
Hello, as per the ...harlan4096 — 07:21

[-]
Birthdays
Today's Birthdays
avatar (44)lamSouse
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (41)alapesihy
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>