4 ms·
But how did they infect Sumatra PDF reader? My copy has a digital signature in the .EXE. Do they run copycat sites and distribute Sumatra from there? These arti
by favourable 4y ago
But how did they infect Sumatra PDF reader? My copy has a digital signature in the .EXE. Do they run copycat sites and distribute Sumatra from there? These articles are always skimpy on the details of how software gets infected.
- lioeters 4y agoMore technical details: https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/ https://www.microsoft.com/security/blog/2022/09/29/zinc-weap... It seems the "trojanized" software was manually installed by people on the inside who were tricked into doing so. Attack flow diagram for recent ZINC campaign: 1. Initial compromise - Target contacted via social media 2. Execution - ISO file containing trojanized PuTTY or KiTTY delivered -> User inputs SSH destination IP, username, password from a text file -> Connects to an actor-controlled SSH server and installs the backdoor 3. ..Persistence, command and control, data collection..