Sinisterly
Password-Stealing Malware New Way To Infecting PCs - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: World News (https://sinister.li/Forum-World-News)
+--- Thread: Password-Stealing Malware New Way To Infecting PCs (/Thread-Password-Stealing-Malware-New-Way-To-Infecting-PCs)



Password-Stealing Malware New Way To Infecting PCs - mothered - 07-05-2018

Greetings to all,

Although the malware Is quite a few years old, It's now emerged with a new form of Infection via a good old code Injection, but In an Impressive manner. Also checkout the phishing email In the article, It does appear rather authentic.

Quote:A powerful form of malware which can be used to distribute threats including Trojans, ransomware and malicious cryptocurrency mining software has been updated with a new technique which has rarely been seen in the wild.

Distributed in spam email phishing campaigns, Smoke Loader has been sporadically active since 2011 but has continually evolved.

What intrigued researchers is how Smoke Loader is now using an injection technique which hadn't been used to distribute malware until just days ago. The code injection technique is known as PROPagate and was first described as a potential means of compromise late last year.

This technique abuses the SetWindowsSubclass function - a process used to install or update subclass windows running on the system - and can be used to modify the properties of windows running in the same session. This can be used to inject code and drop files while also hiding the fact it has happened, making it a useful, stealthy attack.

Source.