Automatically translated.View original post

Beware of fake Zoom apps. Use hacked certificates.

Beware of fake Zoom apps. Use hacked certificates to smuggle malware onto victim machines.

The Zoom application, although not as popular today as during the COVID era, is still an application adopted by many companies in online meetings or job interviews, and as it is still popular among businesses, hackers have taken advantage of this point to release malware.

According to a report by the website, Hackread has mentioned the detection of phishing deception campaigns to release malware on victims of office workers, using fake applications like Zoom and Microsoft Teams (as well as popular document reading applications like Adove Acrobat) as decoys, because the target audience is often a group that has to have meetings with companies or frequent customer appointments. The campaign was detected in February by a research team from Microsoft Defender Security Research Team, a research agency focused on researching Microsoft's cybersecurity methods.

The research team has revealed that the campaign will start with hackers sending phishing emails in the form of meeting links or blurred PDF documents. After pressed, the link or link inside the document will take the website to download the fake application. The website will deceive the victim that the victim is unable to attend the meeting or read the document because the application is too old. Download the update to install it.

And to create trust for installation files like msteams.exe or adobereader.exe, they are "signed" with a Trusted Certificate that has been hacked by hackers. This campaign will use the TrustConnect Software PTY LTD certificate. The certificate is an Extended Validation Certificate, a type of certificate that is very reliable, allowing the above installation files to break through blocks comfortably.

After the file is processed and installed, it will be installed to install Remote Monitoring and Management (RMM) tools, which are usually tools for IT departments based on organizations to help fix problems on the machine for employees in the organization. In this case, these tools are used as system backdoors or backdoors, so that hackers can log in to the victim's company at any time. In addition to ensuring that this attack lasts for a long time. (Persistence) The PowerShell script inside the fake application will quietly run to install a similar tool. Others, such as ScreenConnect and MeshAgent, guarantee that the company's IT administrator will detect and delete one of them, there are still alternatives to access the system.

When a hacker can be embedded in the system through such tools, it leads to other operations, such as password theft or ransom malware release or Ransomware to the system to continue threatening calls from the victim company.

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # zoom

3/25 Edited to

... Read moreในยุคที่เราต้องพึ่งพาเทคโนโลยีเพื่อทำงานจากระยะไกล แอปสำหรับประชุมออนไลน์อย่าง Zoom ยังคงเป็นเครื่องมือสำคัญสำหรับบริษัทและองค์กรต่างๆ แม้ว่าความนิยมจะลดลงจากช่วงโควิด-19 แต่ก็ยังมีการใช้งานอย่างต่อเนื่อง เหตุการณ์แอป Zoom ปลอมที่ถูกเซ็นรับรองด้วยใบรับรองดิจิทัลที่ถูกแฮกมา ช่วยหลอกให้ผู้ใช้ดาวน์โหลดไฟล์ติดตั้งมัลแวร์เป็นการเตือนให้ตระหนักถึงความเสี่ยงใหม่ๆ ที่นักแฮกใช้เทคนิคซับซ้อน เพื่อโจมตีเป้าหมายในองค์กร ประสบการณ์ของหลายคนที่เคยได้รับอีเมลเชิญเข้าประชุมพร้อมไฟล์แนบหรือไฟล์ PDF ที่ดูเหมือนสำคัญ แต่เมื่อเปิดแล้วกลับพบว่ามีลิงก์พาไปยังเว็บไซต์ปลอมเพื่อดาวน์โหลดโปรแกรมอัปเดต ถึงแม้หน้าตาแอปจะเหมือนตัวจริงก็ตาม แต่ความน่ากลัวคือ แอปเหล่านี้ถูกเซ็นรับรองด้วยใบรับรองระดับขยายการตรวจสอบ (Extended Validation) ที่ทำให้ระบบมาตรฐานหลายอย่างมองว่าแอปนี้ปลอดภัย ผู้ใช้จึงไม่ระวังส่งผลให้มัลแวร์สามารถฝังตัวและติดตั้งเครื่องมือ Remote Monitoring and Management (RMM) ซึ่งใช้เป็นช่องทางให้แฮกเกอร์เข้าควบคุมเครื่องและระบบได้ตลอดเวลาอย่างเงียบเชียบ สิ่งที่แนะนำอย่างยิ่งคือการเพิ่มความระมัดระวังในการคลิกลิงก์และดาวน์โหลดไฟล์จากแหล่งที่ไม่น่าเชื่อถือ ตรวจสอบอีเมลอย่างละเอียดโดยเฉพาะที่เกี่ยวข้องกับการประชุมหรือติดต่อธุรกิจ หากรับไม่ตรงกับปกติหรือมีข้อความผิดเพี้ยน ให้ยืนยันกับผู้ส่งก่อนทุกครั้ง รวมถึงตรวจเช็คความถูกต้องของเว็บไซต์ที่ดาวน์โหลดแอปหรือไฟล์ด้วยเทคนิคเช่นดู URL ว่าตรงกับเว็บไซต์ทางการหรือไม่ นอกจากนั้น องค์กรควรตั้งค่าการรักษาความปลอดภัยของระบบให้เข้มงวด เช่น อัปเดตซอฟต์แวร์อยู่เสมอ ใช้ระบบป้องกันมัลแวร์ที่มีประสิทธิภาพ และให้ความรู้พนักงานเกี่ยวกับเทคนิคการฟิชชิ่งและมัลแวร์จากแอปปลอม เพื่อป้องกันไม่ให้ตกเป็นเหยื่อของการโจมตีที่ซับซ้อนเหล่านี้ได้ในอนาคต การเข้าใจและรู้จักกับภัยคุกคามไซเบอร์รูปแบบใหม่ รวมถึงวิธีการที่แฮกเกอร์ใช้ใบรับรองที่ถูกขโมยมา เป็นสิ่งสำคัญสำหรับทุกคนในยุคดิจิทัล เพื่อให้เราไม่ตกเป็นเหยื่อและก้าวไปพร้อมกับมาตรการรักษาความปลอดภัยที่เข้มแข็งขึ้นอย่างต่อเนื่อง