3 ms·
Numerous orgs hacked after installing weaponized open source apps
- favourable 4y agoBut how did they infect Sumatra PDF reader? My copy has a digital signature in the .EXE. Do they run copycat sites and distribute Sumatra from there? These articles are always skimpy on the details of how software gets infected.
- lioeters 4y agoMore technical details: https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/ https://www.microsoft.com/security/blog/2022/09/29/zinc-weap... It seems the "trojanized" software was manually installed by people on the inside who were tricked into doing so. Attack flow diagram for recent ZINC campaign: 1. Initial compromise - Target contacted via social media 2. Execution - ISO file containing trojanized PuTTY or KiTTY delivered -> User inputs SSH destination IP, username, password from a text file -> Connects to an actor-controlled SSH server and installs the backdoor 3. ..Persistence, command and control, data collection..