HomeSecurityBeware of the malicious version of the popular PuTTY application

Beware of malicious version of popular PuTTY application

A malicious version of the popular SSH (Secure shell) application PuTTY has been crafted by cybercriminals and its code has been developed in such a way as to steal credentials used to remotely access servers.

PuTTY is a popular, free and open source program. It works in Windows and Unix environments, and is mainly used for encrypted communication with remote machines often with Linux / Unix operating systems.

Beware of malicious version of popular PuTTY application

 

PuTTY is frequently used by system administrators, web developers, and database administrators around the world.

Cybercriminals have reassembled a Trojanized copy of PuTTY that has been circulating online since 2013.

In this hacked version of PuTTY, connection data is collected when the administrator connects to a remote computer and delivered to the attacker's web server.

Security researchers from Symantec first spotted the unofficial release in late 2013.

Dumitru Stama from Symantec says that security programs have PuTTY on their whitelist as its connections are generally considered trusted due to the program's use by system administrators.

The "bad" copy can be identified by looking at the information in the "about" section of the program, which reads as follows: "Unidentified build, Nov 29 2013 21:41:02"

PuTTY

The unofficial and at the same time hacked version is much larger in volume than the latest legal version, which should set off an alarm in security programs, even if they are fully updated.

Stama says that the company's telemetry data shows that there is a limited spread of the Trojanized version, and it is not from a single specific region or industry sector, which suggests that it is not being used for targeted attacks.

You can download the malicious copy if you search the internet for the program in question, and the search results include malicious websites.

If the victim chooses one of the hacked websites that unknowingly deliver the malicious application, they will download the malicious version after several redirects. The last of these is to an IP address in the United Arab Emirates.

Every time the victim connects to a remote location, the credentials are immediately delivered to the attacker, who can then connect in turn whenever he wants.

A simple method of protection is to check the source of the download and to make sure that the package comes from the official website.

 

Source: iguru

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS