Trojanized TeamViewer used in government, embassy attacks across Europe
#1
Quote:A new, targeted attack weaponizing TeamViewer has been uncovered which focuses on stealing financial information belonging to governmental and financial targets across Europe and beyond.
 
Researchers from Check Point said on Monday that the campaign is specifically targeting officials in government finance capacities and embassy representatives in Europe, alongside Nepal, Kenya, Liberia, Lebanon, Guyana, and Bermuda.
 
The infection vector begins with a typical phishing email containing a malicious attachment claiming to be a "Top Secret" document from the United States. 
 
The email sent to potential victims contains the subject line "Military Financing Program" and the .XLSM document attached to the message has been crafted with a logo from the US Department of State in a bid to appear legitimate.

If a target downloads and opens the attachment, they are asked to enable macros -- a very common method employed by attackers to gain access to a victim system. Should they do so, two files are extracted -- a legitimate AutoHotkeyU32.exe program and a malicious TeamViewer DLL.

SOURCE: https://www.zdnet.com/article/trojanized...ss-europe/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.3.5 / 19.3.6 Update
Changes in 19.3.6:...harlan4096 — 11:55
AVG 25.12.10659
AVG 25.12.10659: ...harlan4096 — 11:54
Avast 25.12.10659
Avast 25.12.10659:...harlan4096 — 11:53
Microsoft Edge 143.0.3650.80
Version 143.0.3650...harlan4096 — 11:52
Audacity 3.7.7
Audacity 3.7.7 ...harlan4096 — 11:50

[-]
Birthdays
Today's Birthdays
avatar (41)Enlargedterrestrial20
Upcoming Birthdays
avatar (43)ivyhuv

[-]
Online Staff
There are no staff members currently online.

>