Beware of DarkGate Loader scams in Microsoft Teams


What you need to know

  • Hackers are leveraging a new phishing campaign dubbed ‘DarkGate Loader’ to compromise Microsoft Teams accounts.
  • The technique is designed to dupe unsuspecting users into downloading and opening .ZIP files marked ‘Changes to the vacation schedule‘ onto their devices.
  • The disguised download process uses Windows cURL, and the pre-compiled script makes it harder to spot the malware since the code is hidden.

Hackers are leveraging sophisticated techniques to dupe and lure unsuspecting users into their malicious attacks. Toward the end of August, Truesec’s research team started investigating a new process dubbed ‘DarkGate Loader.’

This phishing campaign sends seemingly harmless messages to Microsoft Teams users. The hackers used compromised Office 365 accounts to send messages with harmful attachments to unsuspecting users to trick them into downloading and opening ZIP files marked ‘Changes to the vacation schedule.

Be aware that clicking on this ZIP file automatically initiates a download process from a SharePoint URL containing an LNK file disguised as a PDF document (via TechRadar.) 

A screenshot of a SharePoint site hosting the file Changes to the vacation schedule.zip. (Image credit: Trusec)

Trusec highlighted the hijacked accounts used by the hackers: “Akkaravit Tattamanas” (63090101@my.buu.ac.th) and “ABNER DAVID RIVERA ROJAS” (adriverar@unadvirtual.edu.co), sending malicious VBScript lurking inside the LNK file which in turn deploys the malware known as DarkGate Loader.





Source link

Previous article8 great Zoom features you (probably) don’t know about
Next articleAssessing the effect of Bitcoin’s pre- halving on Ethereum