Microsoft Spots Nodersok Malware Campaign That Zombifies PCs
#1
Bug 
Quote:A new fileless malicious campaign, dubbed Nodersok by Microsoft Defender ATP Research Team researchers who discovered it, drops its own LOLBins to infect Windows computers with a Node.js-based malware that will turn the devices into proxies.
 
Unlike other fileless malware attacks that only use living-off-the-land binaries (LOLBins) present on the devices they compromise, the attackers behind Nodersok have been observed while also delivering the legitimate Node.exe Node.js framework and the Windows Packet Divert (WinDivert) network packet capture tool to devices they target.
 
The campaign attacked thousands of machines within several weeks, with a focus on home users from U.S. and Europe, with roughly 3% of all attacks also targeting organization from industry sectors such as education, business and professional services, healthcare, finance, and retail.

Read more here: https://www.bleepingcomputer.com/news/se...ifies-pcs/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply
#2
Quote:A newly discovered strain of malware transforms PCs into what Microsoft ominously calls “zombie proxies” using otherwise legitimate programs, and the company claims it’s infected thousands of computers across the U.S. and Europe.

Microsoft and Cisco’s Talos researchers both released reports this week that outlined this cyber threat, which the companies call Nodersok and “Divergent” respectively.

Source(full read) https://gizmodo.com/microsoft-cisco-talo...1838602134
[-] The following 1 user says Thank You to dhruv2193 for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 151.0.1
Mozilla Firefox Br...harlan4096 — 08:57
AnyDesk 9.7.4 for Windows
Version 9.7.4 for ...harlan4096 — 08:55
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 08:52
Brave 1.90.124 (Chromium 148.0.7778.179)
Release v1.90.124 ...harlan4096 — 08:49
Screenpresso 2.2.12
Screenpresso 2.2.1...harlan4096 — 08:42

[-]
Birthdays
Today's Birthdays
avatar (50)Mirzojap
avatar (36)idilysaju
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>