HomeSecurityMicrosoft: Fixes bug that allows ransomware installation

Microsoft: Fixes bug that allows ransomware installation

Microsoft has patched a security flaw that criminals exploited to bypass Windows ' SmartScreen security feature and install Magniber ransomware and Qbot malware .

See also: Microsoft drivers: Used for ransomware attacks

Microsoft

The attackers wrote malicious standalone JavaScript to exploit the CVE-2022-44698 zero-day, which bypasses Mark-of-the-Web. These warnings are displayed by Windows and inform users that files originating from the Internet should be approached with caution.

According to Microsoft, this security flaw can only be exploited through these three attack vectors:

  • If an attacker hosts a malicious website, they could easily exploit the vulnerability.
  • If an attacker sends a targeted user a specially crafted .url file, via instant message or email.
  • Websites that have been compromised or websites that allow user-generated content may contain malicious code specifically designed to exploit security vulnerabilities.

In each scenario, criminals would need to trick their victims into downloading harmful files or visiting malicious websites with the CVE-2022-44698 exploit.

See also: Play ransomware: Claimed responsibility for the attack in Antwerp

Microsoft has been working on fixing this actively exploited zero-day vulnerability since late October and released security updates to address it during the December 2022 Patch Tuesday.

ransomware

HP's threat intelligence team discovered in October that phishing were distributing the Magniber ransomware using stand-alone JavaScript files that were digitally signed in a malicious manner, which was discovered by Will Dormann , a senior vulnerability analyst at ANALYGENCE.

If this happens, SmartCheck will not function properly and will allow malicious files to run without security warnings. This will allow the Magniber ransomware to install, even though it has been flagged by MoTW.

The Magniber gang has gained a reputation for exploiting security vulnerabilities to infiltrate systems and then unleash ransomware. The malware, known as single-client ransomware, demands $2,500 from its victims. Previously, Magniber was primarily distributed via MSI and EXE files. However, in September 2022, HP Wolf Security began seeing campaigns distributing the ransomware via JavaScript files.

See also: Silence hackers: Attacks with TrueBot malware and Clop ransomware

It is important for both business owners and individual users to take proactive steps to protect themselves from this threat by ensuring that all systems are up-to-date with security patches and that an antivirus program is installed on computers at all times. This will minimize the risk of falling victim to one of these attacks and ensure that any potential threats are quickly identified before they can cause any real damage.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS