HomeSecurityHackers execute malicious scripts using MSI files

Hackers execute malicious scripts using MSI files

Hackers Hackers are very inventive when they want to launch an attack. They are constantly looking for vulnerabilities, "tampering" files to serve their purposes, and much more. This time, some hackers are using malicious MSI files, which download and execute malicious files that bypass conventional security systems.

Malware can disable systems and target financial systems located in specific locations.

As discovered by researchers from the security company TrendMicro, the hackers transferred the malicious * .msi files via spam emails. The malicious files contained JScript / VBScript code.

The malicious JS code is embedded in the * .msi file and downloads the text and other files from the Amazonaws server. Usually the files contained in the malicious software have names such as Jesus or dump. The text file is named desktop.txt, desktop and desktop.ini.

Initially, a spam email is sent to the victim, which contains a malicious attachment. If the victim opens the attachment, then their system will be infected.

According to the research, the hackers target users in Brazil and Portugal, mainly financial organizations and institutions, with the purpose of extracting information.

Hackers execute malicious scripts using MSI files

Hackers use MSI files to bypass the security solutions used by most organizations. MSI files «disguise» themselves as Adobe Acrobat Reader DC and lead users to the Portuguese website.

Researchers believe that hackers use different methods on their victims in Brazil and Portugal.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS