AZORult: Now, as A Signed “Google Update”

Discussion in 'malware problems & news' started by guest, Jan 28, 2019.

  1. guest

    guest Guest

    AZORult: Now, as A Signed “Google Update”
    January 28, 2019
    https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    This is sneaky indeed. So it's best to only trust a handful of certificates, and I wonder how you can stop apps from replacing legitimate apps inside C:\Program Files. This is something that should not have been possible in Windows, you should not be able to modify folders that do not belong to you! But a good HIPS would alert that the GoogleUpdate.exe app had been changed, they monitor this via checksum.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.