Bitcoin Forum
May 10, 2024, 12:12:56 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [13/10/2018] PSA: Hackers Are Using Fake Flash Updates to Hide Crypto Malware  (Read 157 times)
Lmaooo (OP)
Full Member
***
Offline Offline

Activity: 694
Merit: 108


santacoin.io


View Profile
October 13, 2018, 09:50:56 PM
 #1

PSA: Hackers Are Using Fake Flash Updates to Hide Cryptocurrency Mining Malware

It has been discovered that fake Adobe Flash updates are being used to surreptitiously install cryptocurrency mining malware on computers and networks, creating severe losses in time, system performance, and power consumption for affected users.


Cryptojacking Breaks New Ground

While fake Flash updates that push malware have traditionally been easy to spot and avoid, a new campaign has employed new tricks that stealthily download cryptocurrency miners on Windows systems.

Writing in a post exposing the scheme, Unit 42 threat intelligence analyst Brad Duncan said:

    “As early as August 2018, some samples impersonating Flash updates have borrowed pop-up notifications from the official Adobe installer. These fake Flash updates install unwanted programs like an XMRig cryptocurrency miner, but this malware can also update a victim’s Flash Player to the latest version.”

The implication of this unpleasant scenario is that a potential victim may not notice anything out of the ordinary while an XMRig cryptocurrency miner or other unwanted program is quietly running in the background of the victim’s Windows computer. This miner software could potentially slow down the processor of the victim’s computer, damage the hard drive, or extract confidential data and transmit it onto other digital platforms without the victim’s consent.


Technical Details of Fake Adobe Update Cryptojacking Malware

Duncan explained that it was not very clear how potential victims were arriving at the URLs delivering the fake Flash updates; however, network traffic during the infection process has been primarily related to fraudulent Flash updates. Interestingly, the infected Windows server generates an HTTP POST request to [osdsoft[.]com], a domain affiliated with updaters or installers pushing cryptocurrency miners.

He said while the research team searched for certain particular fake Flash updates, it observed some Windows executables file with names starting with Adobe Flash Player from non-Adobe, cloud-based web servers. These downloads usually had the string “flashplayer_down.php?clickid=” in the URL. The teams also found 113 examples of malware meeting these criteria since March 2018 in AutoFocus. 77 of these malware samples are identified with a CoinMiner tag in AutoFocus. The remaining 36 samples share other tags with those 77 CoinMiner-related executables.

Duncan encouraged Windows users to be more cautious about the kind of Adobe Flash updates that they try to install, stating that while the Adobe pop-up and update features make the fake installer seem more legitimate, potential victims will still receive warning signs about running downloaded files on their Windows computer.

In his words:

    “Organizations with decent web filtering and educated users have a much lower risk of infection by these fake updates.”

CCN recently reported that a report from McAfee labs showed that cryptojacking surged 86 percent in the second quarter of 2018, and is up 459 percent in 2018 so far over the whole of 2017.

reference: https://www.ccn.com/psa-hackers-are-using-fake-flash-updates-to-hide-cryptocurrency-mining-malware/


1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
Bitcoin mining is now a specialized and very risky industry, just like gold mining. Amateur miners are unlikely to make much money, and may even lose money. Bitcoin is much more than just mining, though!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
1715343176
Hero Member
*
Offline Offline

Posts: 1715343176

View Profile Personal Message (Offline)

Ignore
1715343176
Reply with quote  #2

1715343176
Report to moderator
hatshepsut93
Legendary
*
Offline Offline

Activity: 2968
Merit: 2147



View Profile
October 13, 2018, 10:08:59 PM
 #2

Flash has so much vulnerabilities that I've stopped updating and using it a few years ago, and if some site tells me that I need flash, I just look for an alternative site. Also, Flash is just obsolete, modern browsers have everything you need built-in: rendering, video, audio, etc. But generally it's better to surf the web with some no-script add-on and enable scripts only on the sites you trust.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!