Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Use Windows? You might be part of a malicious proxy network

  • August 17, 2023
Total
0
Shares
0
0
0


Your computer may be part of a major proxy service without you even knowing. To make matters worse, someone out there is getting paid to offer these IP addresses, and the bandwidth, to their customers.

These are the findings of AT&T Alien Labs, published earlier this week. As reported by BleepingComputer, a threat actor created a piece of malware and distributed it through game cracks and other illegal software. 

The malware silently downloads and installs a proxy application, without user knowledge or consent. Antivirus programs weren’t flagging the proxy application as malicious, either.

Hundreds of thousands of victims

When the installation is complete, the infected endpoint becomes part of a proxy network which the malware’s operators then sold as a proxy service to its clients and customers. Apparently, more than 400,000 Windows systems were compromised this way. 

To make matters worse, the company behind the botnet claims that all of the victims gave their consent, and willingly became part of the proxy infrastructure. However, researchers at Alien Labs beg to differ: 

“Although the proxy website claims that its exit nodes come only from users who have been informed and agreed to the use of their device, Alien Labs has evidence that malware writers are installing the proxy silently in infected systems.”

They added, “as the proxy application is signed, it has no anti-virus detection, going under the radar of security companies.”

While we don’t know the name of the threat actors behind the campaign, the researchers said it’s almost identical to an earlier campaign targeting macOS systems. In that campaign, a malware named AdLoad was being distributed. 

To double-check whether your device was compromised, AT&T’s researcher says users should look for a “Digital Pulse” executable located at “%AppData%\”, or a similar Registry key found in “HKCU\Software\Microsoft\Windows\CurrentVersion\Run\.” and remove it.

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Starfield has jail for space crimes, devs confirm in new Q&A

  • August 17, 2023
View Post
Next Article
  • News

ULTRARAM will allow you to close your laptop, come back a thousand years later and pick up where you left off

  • August 17, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Sunday, October 1 (game #615)

  • September 30, 2023
View Post
  • News

Mortal Kombat 1 creator teases that a host of terrifyingly familiar faces may be on the way

  • September 30, 2023
View Post
  • News

Google Pixel Buds Pro leak gives us an early look at some new colors

  • September 30, 2023
View Post
  • News

The Pokémon Company apologizes and blames “overwhelming demand” for its Van Gogh collab stock issues

  • September 30, 2023
View Post
  • News

Your next laptop could run faster, last longer and pack more memory thanks to Samsung’s revolutionary new technology — but it won’t be cheap

  • September 30, 2023
View Post
  • News

Early iPhone 16 leak hints at larger screens for the Pro and Pro Max models

  • September 30, 2023
View Post
  • News

Bad news – turns out even long passwords can be cracked easily

  • September 30, 2023
View Post
  • News

AMD has a new trick to make games run smoother – but only for RX 7000 GPUs

  • September 30, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.