HomeSecurityFake Zoom Installers install backdoor on Windows systems

Fake Zoom Installers Install Backdoor on Windows Systems

Zoom Installers

Hackers are exploiting various applications , such as Zoom, to infect systems with malware. Security from Trend Micro have discovered two malware samples that infect Windows systems and present themselves as Zoom installers. The malicious Zoom installers are not distributed through official distribution channels.

Fake Zoom installers

One of these fake Zoom installers installs a backdoor that allows attackers to gain remote access Windows computer the victim's. The second is the Devil Shadow botnet.

The first malicious installer looks very similar to the official version. It contains encrypted files that will decrypt the malware version.

Fake Zoom Installers Install Backdoor on Windows Systems

The malware "kills" the current remote utilities upon installation and opens TCP port 5650 to gain remote access to the infected system.

Windows

In addition, it runs an official zoom installer so as not to arouse suspicion.

The second fake Zoom installer is related to the Devil Shadow Botnet. The infection begins with the malicious installer, with a file called pyclient.cmd that contains malicious commands.

And in this case, hackers include a copy of the official Zoom installer to trick victims. The compromised app installer deploys a malicious archive and code.

The malware sends its C&C collected information every 30 seconds when the computer is turned on. More details about the fake installers can be found here.

In another hacking campaign, attackers used fake Zoom installers to infect victims with the WebMonitor RAT. The infection begins with the download of the malicious ZoomIntsaller.exe from malicious sources.

Due to the coronavirus pandemic, many companies around the world have asked employees to work from home. This new situation has increased the use of video conferencing applications, which has not gone unnoticed by cybercriminals.

However, there are some signs that something is wrong. For example, the above Zoom installers are hosted on suspicious sites and not on official app stores, such as the Play Store, App Store, or Zoom’s download center. Another sign is that the malicious installers install and run the “legitimate Zoom installer” more slowly than the real program. The malicious versions take longer to execute, as they extract the malicious components before Zoom runs.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS