Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

This newly-discovered malware targets Windows to steal sensitive data

  • June 29, 2023
Total
0
Shares
0
0
0


Fortinet has unveiled preliminary details of a ThirdEye, a new info-stealing malware awarded a medium severity level, meaning the risk posed to victims is potentially considerable.

The company’s FortiGuard Labs discovered the stealer when it came across suspicious-looking files in a cursory review. 

The good news is that the analysts believe it not to be sophisticated in nature, but even so, Fortinet suggests that the information stolen from victim machines could go on to be used for future attacks.

ThirdEye infostealer witnessed in the wild

Suspicions were raised when the team found a Russian file name in a file archive. The name, “Табель учета рабочего времени.zip,” translates to timesheet. Inside the zipped folder are two files that pose as documents, but are actually executables. 

The .exe files are designed to target Windows machines, which have long been the subject of attacks. However, recent months have seen many attackers shift their attention to Android devices, with multiple reports of malicious apps being hosted in the Play Store.

When successfully deployed, the malware steals information like BIOS and hardware data and sends it back to its C2 server.

While early versions of the malware, dating back to April, collected little more than client_hash, OS_type, host_name, and user_name, modifications a few weeks later added new parameters targeting CPU and RAM information, network interface data, and BIOS information. 

Fortinet believes that the malware serves the purpose of “understanding and narrowing down potential targets,” and that it might be looking to target Russian victims given the language used and the fact that it was found on a public scanning service from the country.

Currently, the analysts aren’t overly concerned with the malware’s sophistication, but evidence of developments suggest that future versions could be even more intrusive. 


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Your Vizio TV is getting a Netflix-style refresh in a great free update

  • June 29, 2023
View Post
Next Article
  • Technology

Plex lays off 20% of its workforce amid advertising slowdown

  • June 29, 2023
View Post
You May Also Like
View Post
  • News

Royal Family website targeted in apparent Russian cyber attack

  • October 2, 2023
View Post
  • News

Leaked Google Pixel 8 ad shows off its creepy new AI photography feature

  • October 2, 2023
View Post
  • News

This dark fantasy RPG inspired by classic roguelikes is now free on Steam

  • October 2, 2023
View Post
  • News

The road to Skynet – NSA to start AI security center

  • October 2, 2023
View Post
  • News

Join the flip side with the Samsung Galaxy Z Flip5 and Samsung Galaxy Z Fold5

  • October 2, 2023
View Post
  • News

Austrian Audio’s high-end headphones and amp is a setup for serious audiophiles

  • October 2, 2023
View Post
  • News

Good news, Apple fans! iPhone 15 wait times have reduced significantly

  • October 2, 2023
View Post
  • News

Many firms are struggling to keep up with their cloud and security work

  • October 2, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.