Beware of fake IT Support teams tricked into installing malware.
Warning Beware of Fake IT Support Team Tricked into Installing EtherRAT Malware
According to a report by the website, Bleeping Computer has mentioned the detection of a remote access Trojan malware release campaign called EtherRAT to infiltrate the systems of companies and organizations by impersonating IT Support teams to deceive employees in targeted organizations to install malware. The UNIT 42 research team from renowned networking expert Palo Alto has revealed that the campaign will start with phishing scams through email, with an employee questionnaire or "Employee Survey" with a PDF file that contains malware.
After the victim opens the file, the victim will be contacted in the form of a Voice Call via Microsoft Teams from an external account that claims to be the administrator or "System Administrator," which usually uses an email address such as helpdesk@Progressive936.onmicrosoft [.] com, etc. The hacker will trick the victim into accessing the victim machine through Microsoft Teams' Share Screen feature to install Remote Desktop tools such as HopToDesk and AnyDesk. After the hacker has remotely accessed the victim's machine, the hacker will download it. A malware installation file in the MSI package format named v7.msi comes down from the camorreado domain. [.] Click by that malware is not yet a real EtherRAT malware, but just a successor malware (Loader) that will download the real malware file (Payload) in a JavaScript file format named Node.js down to install via Runtime.
EtherRAT malware can be called malicious by the adoption of intelligent contract features or Ethereum's Blockchain network SmartContracts to receive commands from C2 or Command and Control servers. This malware also has many capabilities, such as file theft, file manipulation, and system persistence.
# microsoft # Trending # lemon 8 diary # itsupport # freedomhack

































































