HomeSecurityFallout exploit kit continues to infect systems with malware

Fallout exploit kit still infects systems with malware

Fallout

The Fallout exploit kit was first discovered five months ago and is still infecting internet users today. Fallout is often found on websites that have been hacked, having entered them by exploiting known vulnerabilities and having installed malware on the host. Those who visit these hacked websites are at risk of being infected with ransomware or infostealers, and in the case of the Fallout exploit kit, researchers at Cybereason warn that it is the GandCrab ransomware and the AZORult infostealer.

Infection is achieved by simply browsing a hacked website, without any further action required from the victim. The malicious code is automatically executed to download the malware to the visitor's machine, and then the malware runs in the background. Through XSS or Flash Player, the malicious actors create multiple redirects that lead the victim to the desired landing page, which then activates the infection code. According to the researchers, most of the hacked pages are on porn sites due to the high popularity of these sites, as well as the fact that many of their administrators do not update the third-party tools and plugins they use.

Once the victim’s machine is accessed, Fallout executes a PowerShell script to run base64 encoded commands and execute the final payload. Using PowerShell helps to avoid AV detection, or more specifically, Windows Antimalware protection. Of the two payloads, GandGrab has recently been addressed by BitDefender , and while users will have to go through the tedious process of decrypting their files, its threat is no longer effective. On the other hand, AZOR is much more dangerous for those who are not prepared to deal with it.

Fallout exploit kit still infects systems with malware

AZORult can steal bitcoin wallet IDs, locally stored files, cached or hidden login credentials and related data, web cookies from a set of different browsers, and more. It is a sophisticated infostealer that is popular with cybercriminals, used in sextortion campaigns, email spamming campaigns, and even fake VPN. To address the problem of dangerous browsing, users should use robust anti-malware tools from reputable vendors, and webmasters should make sure their software is up to date and that they only use the components and third-party software that they really need.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS