Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Malvertising targeting Chinese users using fake Notepad++ and VNote installers
    Cyber Security

    Malvertising targeting Chinese users using fake Notepad++ and VNote installers

    techempireBy techempire1 Comment2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 15, 2024Editorial DepartmentMalvertising/Threat Intelligence

    Notepad++ and VNote installer

    Chinese users looking for legitimate software like Notepad++ and VNote on search engines like Baidu are being targeted by malvertising and fake links that distribute Trojanized versions of the software and ultimately deploy Geacon, a Golang-based Cobalt Strike implementation. .

    Kaspersky researcher Sergey Puzan said: “The malicious websites found in notepad++ searches are distributed via advertising blocks.”

    “Opening it, attentive users will immediately notice an interesting inconsistency: the website address contains a vnote line, the title offers a download of Notepad‐‐ (an analogue of Notepad++, also distributed as open source software), and the image proudly displays Notepad++. In fact, Notepad is included in the package downloaded from here.”

    Internet security

    The website is called vnote.fuwenkeji[.]cn, contains download links for the Windows, Linux, and macOS versions of the software, with the Windows variant linking to the official Gitee repository containing the Notepad–installer (“Notepad–v2.10.0-plugin-Installer.exe” ).

    On the other hand, the Linux and macOS versions lead to malicious installation packages hosted on vnote-1321786806.cos.ap-hongkong.myqcloud[.]com.

    Notepad++ and VNote installer

    In a similar manner, VNote’s fake website (“vnote[.]Messages” and “vnotepad[.]com”) results in the same group myqcloud[.]com link, in this case, also points to the Windows installer hosted on the domain. In other words, links to potentially malicious versions of VNote are no longer valid.

    Analysis of the modified Notepad installers revealed that they are designed to retrieve next-stage payloads from remote servers, a backdoor similar to Geacon.

    Internet security

    It can create SSH connections, perform file operations, enumerate processes, access clipboard contents, execute files, upload and download files, take screenshots, and even enter sleep mode. Facilitates command and control (C2) via the HTTPS protocol.

    At the same time, malvertising campaigns also used MSIX installer files disguised as Microsoft OneNote, Notion, and Trello to spread other malware, such as FakeBat (also known as EugenLoader) malware.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.