HomeSecurityExploit kits target Windows users with Ransomware and Trojans

Exploit kits target Windows users with Ransomware and Trojans

Exploit kits target Windows users with Ransomware and Trojans

In recent days, four new malicious campaigns have surfaced, redirecting users to exploit kits, with the aim of installing Trojans and ransomware on their devices.

The malicious campaigns were discovered by expert nao_sec and are distributed via malvertising, which redirects visitors to pages with exploit kits. These landing pages are typically hosted on compromised websites.

When a user visits one of these websites, the hacked exploit kits attempt to exploit vulnerabilities in their browser to install a malicious program.

The GrandSoft exploit kit installs the Ramnit trojan, as nao_sec discovered last Saturday.

Ramnit is a password-stealing trojan that attempts to steal saved login credentials, online banking credentials, FTP accounts, browser history, and more from its victims.

The Rig exploit kit installs Amadey and a clipboard hijacker.

nao_sec discovered another malware campaign on Sunday, redirecting users to the Rig exploit kit. This one targets CVE-2018-15982 (Flash Player), CVE-2018-8174 (Microsoft Internet Explorer VBScript Engine), and other vulnerabilities to infect users with malware.

When user nao_sec discovered this campaign, it was installing clipboard hijackers, which monitor the Windows clipboard for addresses and replace anything it finds with addresses under its control. This is used to steal money that users believe they are sending to legitimate addresses when making purchases.

Fallout exploit kit installs clipboard hijacker

Earlier today, nao_sec discovered Fallout, which targets vulnerabilities CVE-2018-8174 (Microsoft Internet Explorer VBScript Engine) and CVE-2018-15982 (Flash Player).

Finally, nao_sec discovered another malicious campaign in the Radio exploit kit, which installs the Nemty Ransomware. Nemty targets the CVE-2016-0189 vulnerability in JScript and VBScript for Internet Explorer, which Microsoft patched in 2016.

How will you protect yourself?

For an exploit kit to work, it must identify vulnerabilities to exploit.

Therefore, your best defense is to make sure you always have the latest security updates installed, both for your operating system and any software you have installed.

When focusing on software updates, it's important to update programs that interact with a browser to add extra functionality, such as Adobe Flash, PDF Readers, and other similar programs.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS