According to new evidence, backdoor and trojan malware is being distributed through a new phishing technique, which attempts to lure victims into accepting a certificate “update.” security website
Certificate Authorities (CAs) distribute SSL/TLS security certificates for improved security on the internet, providing encryption for communication channels between a browser and a server.
There have been several cases of certificate abuse over the years, but now a new phishing technique is being used to distribute malware.
On Thursday, Kaspersky researchers reported that the new technique has been detected on multiple sites . The first victims infected with the malware were detected on January 16, 2020.
Visitors to an infected domain see the following image:
The warning states that the site's security certificate is out of date, but although this is a matter for the domain owner, victims are asked to install a " security" to proceed.
The message is contained in an iframe and the content is loaded via a jquery.js script from a third-party command-and-control (C2) server, while the URL bar still maintains the legitimate domain address, so that users do not understand that something is wrong.
“The jquery.js script wraps an iframe that is exactly the same size as the page,” the researchers say. “As a result, instead of the original page, the user sees a seemingly authentic banner that requests the immediate installation of an updated certificate.”.
If the victim presses the button to update, a file, Certificate_Update_v02.2020.exe, begins downloading.
When installed, the executable file will deliver one of two malware to the victim: Mokes or Buerak.
Mokes is a macOS/ Windows backdoor malware, considered “sophisticated” as it can execute malicious code, take screenshots, steal computer information such as files , sounds, and videos , while using AES-256 encryption to cover its activities.
On the other hand, Buerak is a Windows-based Trojan malware that is capable of executing code, hijacking processes, stealing content, and more.

