Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Indian software company’s products hacked to spread data-stealing malware
Global Security

Indian software company’s products hacked to spread data-stealing malware

AdminBy AdminJuly 7, 2024No Comments2 Mins Read
Data-Stealing Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 1, 2024Information hallSupply Chain Attack / Threat Intelligence

Malware that steals data

Installers for three different software products developed by Indian company Conceptworld have been trojanized to spread information-stealing malware.

The installers are Notezilla, RecentX, and Copywhiz, according to cybersecurity firm Rapid7, which discovered the supply chain breach on June 18, 2024. The problem has since been patched by Conceptworld as of June 24 within 12 hours of responsible disclosure.

“The installers have been trojanized to run malware that steals information and has the ability to download and run additional payloads,” the company said in a statement. saidadding that the malicious versions have a larger file size than their legitimate counterparts.

Specifically, the malware is designed to steal browser credentials and cryptocurrency wallet information, log clipboard contents and keystrokes, and download and execute additional payloads on infected Windows hosts. It also configures persistence with a scheduled task to run the main payload every three hours.

Cyber ​​security

It is currently unclear how the official domain “conceptworld(.)com” was hacked to create fake installers. However, once launched, the user will be prompted to proceed with the installation process associated with the actual software, while it is also designed to uninstall and execute the “dllCrt32.exe” binary, which is responsible for executing the “dllCrt.bat” batch script.

In addition to installing security on the machine, it is configured to execute another file (“dllBus32.exe”) which in turn establishes a connection to the command and control server (C2) and includes functionality to steal sensitive data as well as receiving and launching more payloads.

This includes collecting credentials and other information from Google Chrome, Mozilla Firefox, and several cryptocurrency wallets (such as Atomic, Coinomi, Electrum, Exodus, and Guarda). It is also capable of collecting files matching a specific set of extensions (.txt, .doc, .png, and .jpg), logging keystrokes, and capturing clipboard contents.

“The malicious installers observed in this case are unsigned and have a file size that does not match the legitimate installer copies,” Rapid7 said.

Users who downloaded the installer for Notezilla, RecentX, or Copywhiz in June 2024 are advised to check their systems for signs of a breach and take appropriate measures, such as re-imaging the affected ones, to undo the nefarious modifications.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.