According to data collected by Kaspersky researchers , an Iranian hacking group is carrying out new dangerous attacks . The hackers use a PowerShell Script that helps install the Poison Frog backdoor on devices victims' . How does this happen? The malware “disguises” itself as the legitimate application Cisco AnyConnect and is not perceived as dangerous. The hacking group from Iran is the well-known OilRig .
Poison Frog is one of the most powerful backdoors used by these hackers. The group has used it many times to carry out cyber attacks.
Kaspersky researchers have found that hackers are now using a new sample of Poison Frog , which is an executable PE file, written in C#, and its job is to install a PowerShell script containing a backdoor on victims' devices.
The researchers also found a second PowerShell Script, which works in the same way and contains a DNS and HTTP backdoor (Poison Frog HTTP backdoor).
Poison Frog backdoor installation process
OilRig hackers have come up with a clever way to install malware on victims' devices without them realizing it. They present the malware as the legitimate Cisco AnyConnect application.

According to Kaspersky, the hackers have made a small mistake, resulting in a pop-up constantly appearing on the screen, which does not happen with the legitimate application.

The above message helps hackers trick users into believing that there is a problem with their application or internet access . In reality, the hackers have managed to install the Poison Frog backdoor
