Уровень 0 · материалов: 4
В кластер входят документы, предупреждающие об угрозах безопасности, связанных с установкой вредоносного или скомпрометированного программного обеспечения, и не входят документы об общих методах защиты данных без привязки к конкретному ПО.
Общие признаки: предупреждение о вредоносном ПО, кража данных и паролей, использование программ удаленного администрирования, неофициальное или пиратское программное обеспечение, социальная инженерия
Группа выше: Распространение вредоносного ПО обманом
Смысл: The text warns users that pre-installed remote administration software (Radmin) in unofficial Windows builds (ZverCD) is being exploited by hackers to steal money, passwords, and private data.
Users of ZverCD and Radmin are warned that hackers are exploiting weak passwords on port 4899 to steal funds and private data.
Смысл: The text warns against a social engineering scam where attackers trick users into installing remote administration software under the guise of bank support to seize control of their devices.
A user exposes a scam where fake bank employees trick victims into installing remote-control apps from the Play Store to compromise their phones.
Смысл: The text warns about the dangers of using pirated software, specifically a Trojan-infected Windows 7 RC that created a global botnet of 27,000 computers for potential cyberattacks.
A pirated version of Windows 7 RC infected 27,000 computers worldwide, forming a botnet that security firm Damballa eventually mitigated.
Смысл: The main idea is to warn users that 'Zapret 2 GUI' is a malicious piece of software that uses the guise of a useful utility to compromise system security, steal data, and monitor users through hidden certificates and data exfiltration scripts.
A technical investigation reveals that the Zapret 2 GUI fork is actually spyware that disables antivirus, installs root certificates for traffic interception, and steals user data.