Dangerous new phishing campaign infects Windows devices with malicious Linux VM




  • A phishing attack leads to the download of a large file
  • The Linux VM comes preloaded with malware, granting crooks all kinds of advantages
  • Securonix advises caution when handing inbound emails

A creative new phishing technique has been spotted that looks to trick victims into downloading and installing a virtual Linux machine on their Windows endpoints. The virtual machine comes preloaded with a backdoor, granting the crooks unabated access to the compromised devices.

A report from cybersecurity researchers Securonix dubbed the campaign ‘CRON#TRAP’. It starts with a fake “OneAmerica” survey which distributes the VM installation file (285 MB), and a fake error popup image.

https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img