Saturday , November 16 2024
Flow chart

Hacker to use fake Palo Alto GlobalProtect Tool in cyber attack

Trend Micro researchers identified a sophisticated malware campaign that aims at Middle East organizations. The campaign tricks victims into infecting their devices by pretending to be a real Palo Alto GlobalProtect VPN client.

The attack begins with the distribution of a malicious file named “setup.exe,” which masquerades as a legitimate installation package for Palo Alto Networks’ GlobalProtect VPN. Once executed, this file deploys “GlobalProtect.exe” along with configuration files “RTime.conf” and “ApProcessId.conf” into the victim’s system directory, specifically within the path C:\Users\ UserName)\AppData\Local\Programs\PaloAlto\.

Palo Alto Networks Confirms critical RCE zero-day actively exploited

"Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall...
Read More
Palo Alto Networks Confirms critical RCE zero-day actively exploited

CISA, FBI Warns
Hacker compromised multiple teleco network at US

US authorities have revealed a major cyberespionage campaign by hackers, targeting information from Americans in government and politics. The FBI...
Read More
CISA, FBI Warns  Hacker compromised multiple teleco network at US

(CVE-2024-52301)
Laravel Flaw Unveils Millions of Web Applications to Attack

A significant security flaw, CVE-2024-52301, has been found in the Laravel framework, which is widely used for web applications. With...
Read More
(CVE-2024-52301)  Laravel Flaw Unveils Millions of Web Applications to Attack

Bitdefender releases free decryptor for ShrinkLocker ransomware

Bitdefender has released a decryptor for the ShrinkLocker ransomware after months of concern from responders regarding attacks involving this malware....
Read More
Bitdefender releases free decryptor for ShrinkLocker ransomware

Fortinet releases updates for Various Products

Fortinet has issued security updates for several products, including FortiOS, to fix vulnerabilities that could allow cyber attackers to take...
Read More
Fortinet releases updates for Various Products

Microsoft November Patch Tuesday: 4 Zero-Days & 89 flaws

Microsoft's latest Patch Tuesday update fixes 89 security vulnerabilities. Four of these are zero-day vulnerabilities, with two currently being exploited....
Read More
Microsoft November Patch Tuesday: 4 Zero-Days & 89 flaws

CISA Warns of 3 Critical Vulnerabilities in Industrial Control Systems

On November 7, 2024, CISA released advisories about 3 critical security issues, vulnerabilities, and exploits related to Industrial Control Systems...
Read More
CISA Warns of 3 Critical Vulnerabilities in Industrial Control Systems

Cyberattack Disrupts Israel’s Gas and Payment Systems

A cyberattack on an Israeli clearing company on Sunday left some people unable to use their credit cards for shopping...
Read More
Cyberattack Disrupts Israel’s Gas and Payment Systems

Russia blocks thousands websites using Cloudflare’s privacy service

Russia's media censor, Roskomnadzor, has blocked thousands of local websites using Cloudflare's encryption feature that enhances online privacy and security....
Read More
Russia blocks thousands websites using Cloudflare’s privacy service

Hacker to sale Indian Gov.t email credentials

Advertisement for selling the credentials of allegedly belonging to Indian government emails surfaced on the dark web marketplace. A hacker...
Read More
Hacker to sale Indian Gov.t email credentials

The malware deceives by using a command-and-control infrastructure with a new URL named “sharjahconnect.” The URL is designed to look like a legitimate company VPN portal, helping the malware to infiltrate and maintain access to compromised networks without being detected.

A particularly notable aspect of this malware is its use of the Interactsh project, a tool typically used by penetration testers to verify exploit success, for beaconing purposes. By leveraging Interactsh, the malware sends DNS requests to domains within the oast[.]fun domain, such as step[1-6]-{dsktoProcessId}.tdyfbwxngpmixjiqtjjote3k9qwc31dsx.oast.fun. These beaconing requests correspond to various stages of the infection process, from collecting machine information to executing commands received from the C&C server.

This method helps threat actors track their malware’s progress as it spreads, giving them real-time information about which targets have been compromised.

This malware, created in C#, can perform remote PowerShell commands, download and run more payloads, and steal specific files from the infected machine. Its command structure is flexible, enabling it to carry out various tasks.

Executing PowerShell Scripts:
The malware can run PowerShell commands and send the results back to the C&C server.
Process Management:
It can start new processes, download files from a specified URL, and upload stolen files to a remote server.
Data Encryption:
To secure its communications, the malware employs AES encryption, ensuring that data sent to the C&C server is protected from interception.

These capabilities make the malware a powerful tool for spying and stealing data, with the potential to cause serious harm to targeted organizations.

The malware uses smart techniques to avoid being detected by security tools. It checks file paths and specific files before running its main code, making it hard to find in controlled analysis environments. It also uses newly registered domains for its activities, which makes it difficult to detect and attribute the attack to a specific threat actor.

Companies in the Middle East and around the world need to stay alert and take action to improve their defenses against these threats. This means using strong endpoint protection, keeping security protocols up to date, and focusing on educating and raising awareness among employees.

Check Also

flowchart

Hacker to sale Indian Gov.t email credentials

Advertisement for selling the credentials of allegedly belonging to Indian government emails surfaced on the …

Leave a Reply

Your email address will not be published. Required fields are marked *