![]() ![]() ![]() But based on all the knowledge, we don’t think there’s any reason for users to panic.” “2.27 million is certainly a large number, so we’re not downplaying in any way,” Avast chief technology officer (CTO) Ondrej Vlcek told Forbes. It’s possible that the change in company ownership facilitated this supply chain attack. Since the malware binary was digitally signed using a valid certificate issued to the software developer, the attacker was able to breach somewhere in the development process and switch out the production version for the malware version. Piriform confirmed the problem in a blog post. Avast bought Piriform, the utility’s actual developer, in July, which was one month before the poisoned version made its appearance. Supply Chain ProblemĬisco Talos believed that the threat actors compromised Avast’s supply chain. ![]() Cisco evaluated the DGA and sinkholed the domains it produced to prevent them from being used in an attack.įloxif can run other binaries, but there is not yet any evidence that another payload was downloaded and run on the infected systems. The DGA is time-based and can be calculated using the values of year and month. If the primary C&C server does not return a response to the HTTP POST request made by the malware, it uses a domain generation algorithm (DGA) to generate a new location. It only runs on 32-bit systems, which have to be administrator accounts. The malware gleans the computer name, a list of software installed, a list of running processes, MAC addresses for the first three network interfaces and unique IDs that identify each computer. Characteristics of the Malware Attackįloxif is a downloader that gathers information about infected systems and then sends it back to the command-and-control (C&C) server associated with it, reported Bleeping Computer. CCleaner Cloud v was also infected by the malware. 12, was found to contain a multistage malware attack hidden inside of it. Over 2 million users have installed infected versions of a security application owned by software firm Avast.Īccording to Cisco Talos, CCleaner version 5.33, which was available as a legitimate download from Aug. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |