Security company Trustwave has discovered a new malicious campaign that relies on warnings and hoax Windows updates sent via email to infect devices with the Cyborg ransomware.
The attack employs a rather classic approach and starts with an email sent to potential targets and including a fake update attached to the message.
The update, which appears to be using the JPG file extension, is actually an executable file, and once launched, downloads additional payloads from GitHub.
“The file bitcoingenerator.exe will be downloaded from misterbtc2020, a Github account which was active for a few days during our investigation, but is now removed. It is contained under its btcgenerator repository. Just like the attachment, this is .NET compiled malware, the Cyborg ransomware,” Trustwave explains in its analysis of the malicious campaign.
Don’t ...
SOCIAL SHARE CARD GENERATOR