Microsoft: Massive malware campaign delivers fake ransomware

Discussion in 'other security issues & news' started by hawki, May 20, 2021.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "A massive malware campaign pushed the Java-based STRRAT remote access trojan (RAT), known for its data theft capabilities and the ability to fake ransomware attacks...

    In a series of tweets, the Microsoft Security Intelligence team outlined how this 'massive email campaign' spread the fake ransomware payloads using compromised email accounts.

    The spam emails lured the recipients into opening what looked like PDF attachments but instead were images that downloaded the RAT malware when clicked...

    ... The STRRAT malware is designed to fake a ransomware attack while stealing its victims' data in the background."

    https://www.bleepingcomputer.com/ne...ve-malware-campaign-delivers-fake-ransomware/
     
  2. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Wait what

    https://www.bleepstatic.com/images/news/u/1109292/2021/STRRAT-spam-email.png

    That looks damn realistic. And even after you download, it's an IMAGEo_O? That infects youo_O Whaaaaaaaaaaaat

    If I've learned anything, it's to not download any file from email (unless ur friend just called u to tell u he'll send u something and you receive it instantly). They make it look EXACTLY like a pdf, and even after you download it, apparently it's an image that contains a virus waaaaaat
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,648
    Location:
    U.S.A.
    The .pdf attachment is actually a .jar file. Assume a double suffix being deployed; e.g. *.pdf.jar.

    Unless you have Java runtime installed, the .jar file attachment won't open; i.e. run.

    -EDIT- Also per the GData write up, it is noted that Outlook by default blocks opening of .jar attachments.
     
    Last edited: May 20, 2021
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.