Researchers at security firm Flashpoint detected small phishing and spear-phishing campaigns targeting specific recipients. The messages contained macros in document attachments that allowed the download of the Dridex malware.
This User Account Control (UAC) bypass method had gone unobserved until now, the company says. It uses recdisc.exe, which is a Windows default recovery disc executable, while loading of malicious code via impersonated SPP.dll.
Recdisc is one of the applications that is automatically elevated by Windows 7, which makes it even harder to observe by Windows users, especially since it is automatically included on the white-list of applications that are subject to auto-elevation. By riding t...
SOCIAL SHARE CARD GENERATOR