Technology Today

The cybercriminals behind a recent phishing campaign used a fake Norton LifeLock document in order to trick victims into installing a remote access trojan (RAT) on their systems.The infection begins with a Microsoft Word document that contains malicious macros.
However, to get users to enable macros, which are disabled by default, the threat actor behind the campaign used a fake password-protected Norton LifeLock document.Victims are asked to enable macros and type in a password, provided in the phishing email containing the document, to gain access to it.
Palo Alto Networks' Unit 42, which discovered the campaign, also found that the password dialog box accepts only a upper or lowercase letter 'C'.
If the password is incorrect, the malicious action does not continue.If the user does input the correct password, the macro continues executing and builds a command string that installs the legitimate remote control software, NetSupport Manager.The RAT binary is downloaded and installed onto a user's machine with help from the 'msiexec' command in the Windows Installer service.In a new report, the researchers at Palo Alto Networks' Unit 42 explained that the MSI payload installs without any warnings and adds a PowerShell script in the Windows temp folder.
This is used for persistence and the script plays the role of a backup solution for installing NetSupport Manager.Before the script continues its operations, it checks to see if an antivirus from either Avast or AVG is installed on the system.
If this is the case, it stops running on the victim's computer.
If the script finds that these programs aren't present on the machine, it adds the files needed b NetSupport Manager to a folder with a random name and also creates a registry key for the main executable named 'presentationhost.exe' for persistence.Unit 42 first discovered the campaign at the beginning of January and the researchers tracked related activity back to November 2019 which shows that the campaign is part of a larger operation.Via BleepingComputer





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Everyone using Gmail given new inbox warning - watch out for dangerous hidden message


Forget Ring - this Blink doorbell alternative is only £28.99


Leading 20 pieces of tech Brits miss the most - consisting of corded phones and movie video cameras


Everyone utilizing Chrome put on red alert and informed to clear browsing data immediately


Rare deal that rivals Amazon sale sees Samsung Galaxy Smartwatch plummet to £39


Get a free Samsung Galaxy Watch - tech editor shares where to discover it


Fortnite down RECAP: Epic Games release declaration as video game continues to be offline


Top Tech: Sky launches UK's 'fastest broadband' with big 5Gbps fibre upgrade


Virgin Media users alerted they deal with new streaming block - examine your television and act now


All UK WhatsApp users put on alert and provided with immediate pointer this week


Gtech's 'perfect' cordless vacuum package is £& pound; 200 off and makes cleaning 'a lot simpler'


TOWIE's Pete Wicks succumbs to 'fake' Wimbledon influencer who tricked him


Sky summertime sale cuts cost of family essentials but Virgin has something much better


UK Fire television Stick users will be obstructed from popular streaming app on this exact date


Nifty Samsung code gets Galaxy fans this mobile for less


Sky TV block as brand-new crackdown interrupts UK homes from viewing content totally free


Sky's biggest-ever conserving on Gigafast broadband cuts £& pound; 96 off the ultimate upgrade


Google is fixing a major issue with your Gmail inbox, and free upgrade is coming soon


Top Tech: 5 Amazon-rivalling deals from Apple, Samsung, Shark and more


Amazon Prime Day: Favourite tech gizmos and home appliances we actually use and love


Consumers can get an Echo Pop speaker for less than ₤ 6 if they do one easy thing


Sky is dispensing a huge upgrade, however just if your postcode is on this list


Amazon slashes ₤ 450 off Shark self-emptying robotic vacuum in mega Prime Day offer


Newest Kindle hits lowest ever cost in Amazon Prime Day deal with over ₤ 100 off


Samsung unveils new Galaxy, and it makes your current Android phone appearance extremely inferior


Simply hours remain on Virgin Media's complimentary 4K TV deal - act quickly


Everyone with an Android phone placed on red alert as massive new threat validated


The 'finest' smart device of 2025 confirmed - has the iPhone or Android come out on top


Amazon's best Apple deals for Prime Day consisting of iPhone, iPad and AirPods


Tech professional warns 'never state yes' to 3 questions from callers you don't recognise


Millions of Brits 'forced to function as online security guards' for elderly family members