Cybercriminals Distribute Backdoor With VPN Installer
Today, many companies use VPNs for their WFH setups. Although the home is a place for relaxation, users should never let their guard down when it comes to the security of their devices. Virtual Private Networks (VPNs) are also used by cybercriminals as bait for spreading threats and in this attack, threat actors are bundling Windscribe VPN installers with backdoors i.e. known as Backdoor.MSIL.BLADABINDI.THA.
Backdoors allow cybercriminals to gain access and control of computers remotely without the need for proper authentication. The use of a VPN secures the communication between a user’s computer and the internet by encrypting the connection, thus keeping data secure from spying attempts. VPNs have always been useful but are now relied on more than ever as many companies remain in work-from-home (WFH), away from the presumably more secure office network environment.
Indicators of Compromise
URLs
gamezer1hack[.]sytes[.]net:19811
hxxps://onedrive[.]live[.]com/download?cid=9B6546ADF0F7911A&resid=9B6546ADF0F7911A!1195&authkey=ABFIpKKz4bOcT1I
hxxps://yu0aoq[.]db[.]files[.]1drv[.]com/y4mr4XEohBDL_98XqXLIKJPqiyqV1rhPymTxyJlXe0jmdlUfwDD0zTGUJtmAqyLRdtTJXAYycbv00qkSdgyjkAgF7qoUz202MHf4y0SseZXAX-gSTmO3mIT5jCGKwfPRsMgFOcCjm8P9cugtlz0psvZQgiW13JPS_JSu3Wc8nVE0qT8qYTpNjQfCHLwTmNk6fh5zaCvDF0gpJkdKuvrMJ0TsA/dracula.jpg?download&psid=1
File Hash
3b885d93801f89805020bf2c992048ce0dca499809e6721528ee03fa4544b398
c1f32f166400b5e5c394d30e62ee9f0e42c24f2d839c51fda227d2007f499a81
Comments
Post a Comment