Site icon WinCert

Cybercriminals hijacked well known AV software

<p>Well-known Chinese threat actors have been discovered abusing a flaw in a known antivirus application to deliver malware to selected targets in Japan&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3387" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;11&sol;hacker&lowbar;pixabay&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>Cybersecurity researchers from the Kaspersky lab spotted Cicada &lpar;APT10&rpar;&comma; which was tricking employees at various organizations from Japan into downloading compromised versions of the company&&num;8217&semi;s K7Security Suite&period;<&sol;p>&NewLine;<p>Companies that include government agencies and media firms who fall for the trick end up getting LODEINFO&comma; which is a three-year-old malware app that is&comma; among other things&comma; capable of executing PE files and shellcode&comma; killing processes&comma; and uploading and downloading files&period;<&sol;p>&NewLine;<p>Cicada malware has been distributed with a method known as DLL sideloading where the victim first has to download a fake K7Security Suite&period; Interestingly the installation executable itself isn&&num;8217&semi;t malicious&comma; but the folder with installation will usually carry malicious K7SysMn1&period;dll files&period;<&sol;p>&NewLine;<p>K7SysM1&period;dll file is part of the K7Security Suite installation and the setup cannot distinguish the valid vs malicious file&period;<&sol;p>&NewLine;<p>Since the file has been loaded by legitimate security applications&comma; other security software probably won&&num;8217&semi;t be able to detect it as malicious&period;<&sol;p>&NewLine;<p>Security researchers couldn&&num;8217&semi;t determine how many organizations fall for this trick or what is the actual goal of this campaign&comma; although cyber espionage is the most probable answer&period;<&sol;p>&NewLine;

Exit mobile version