Old 04-08-2022, 03:02 AM   #1
vitalker
Human being with feelings
 
vitalker's Avatar
 
Join Date: Dec 2012
Posts: 13,333
Default Delete please

What do you think about it?

https://www.bleepingcomputer.com/new...alware-loader/

Last edited by vitalker; 04-11-2022 at 04:25 AM.
vitalker is offline   Reply With Quote
Old 04-08-2022, 04:35 AM   #2
papagirafe
Human being with feelings
 
papagirafe's Avatar
 
Join Date: Aug 2020
Location: Brasil
Posts: 690
Default

Always possible as any developer might insert malware inadvertently in their installation packages but unlikely IMHO. The same thing has been said about chips manufactured in China that are suspected to include dormant instructions for espionage.
papagirafe is offline   Reply With Quote
Old 04-08-2022, 04:37 AM   #3
vitalker
Human being with feelings
 
vitalker's Avatar
 
Join Date: Dec 2012
Posts: 13,333
Default

Quote:
Originally Posted by papagirafe View Post
The same thing has been said about chips manufactured in China that are suspected to include dormant instructions for espionage.
Why do you think it can't be true? They knew who is the client.
vitalker is offline   Reply With Quote
Old 04-08-2022, 06:38 AM   #4
papagirafe
Human being with feelings
 
papagirafe's Avatar
 
Join Date: Aug 2020
Location: Brasil
Posts: 690
Default

Quote:
Originally Posted by vitalker View Post
Why do you think it can't be true? They knew who is the client.
My initial feeling was only based on the the fact that I've heard so many similar stories in my carrer from dubious websites. But now that I have checked the credential of bleepingcomputer I take it much more seriously. This claim being likely true, I doubt a home/home office setup would be of any interest to the Cicada group and my understanding is that it takes a combination with a vulnerability in a microsoft product used almost only in big entreprises. Still, makes you wonder how many of these exists in other apps...
papagirafe is offline   Reply With Quote
Old 04-08-2022, 07:04 AM   #5
vitalker
Human being with feelings
 
vitalker's Avatar
 
Join Date: Dec 2012
Posts: 13,333
Default

Quote:
Originally Posted by papagirafe View Post
My initial feeling was only based on the the fact that I've heard so many similar stories in my carrer from dubious websites. But now that I have checked the credential of bleepingcomputer I take it much more seriously. This claim being likely true, I doubt a home/home office setup would be of any interest to the Cicada group and my understanding is that it takes a combination with a vulnerability in a microsoft product used almost only in big entreprises. Still, makes you wonder how many of these exists in other apps...
Well they also can use backdoors made for intelligence agencies (not Chinese of course).
vitalker is offline   Reply With Quote
Old 04-11-2022, 02:54 AM   #6
cyrano
Human being with feelings
 
cyrano's Avatar
 
Join Date: Jun 2011
Location: Belgium
Posts: 5,246
Default

Quote:
There is evidence that some initial access to some of the breached networks was through a Microsoft Exchange server...
Once you have access to a server, or a network, the rest is simple and there are numerous options available.

The reason they used VLC is that it's popular and they probably noticed it was present on most targets.
__________________
In a time of deceit telling the truth is a revolutionary act.
George Orwell
cyrano is offline   Reply With Quote
Old 04-11-2022, 03:00 AM   #7
vitalker
Human being with feelings
 
vitalker's Avatar
 
Join Date: Dec 2012
Posts: 13,333
Default

Quote:
Originally Posted by cyrano View Post
Once you have access to a server, or a network, the rest is simple and there are numerous options available.

The reason they used VLC is that it's popular and they probably noticed it was present on most targets.
Yeah, I understand that. So fake news?
vitalker is offline   Reply With Quote
Old 04-11-2022, 04:03 AM   #8
cyrano
Human being with feelings
 
cyrano's Avatar
 
Join Date: Jun 2011
Location: Belgium
Posts: 5,246
Default

Not fake news.

It just amazes me a bit that the media's publicity department didn't cut it. Usually that's what happens.
__________________
In a time of deceit telling the truth is a revolutionary act.
George Orwell
cyrano is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:38 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.