A malvertising campaign has been discovered that deploys a fake PuTTY client to deliver the Rhadamanthys stealer, a dangerous malware . The attackers exploit the trust placed in PuTTY as a widely used SSH and Telnet client by presenting a counterfeit website through malicious ads that appear at the top of Google search results. Let's examine this significant security threat targeting Linux admins more deeply, emphasizing the need for heightened vigilance and robust Linux security measures. . A Closer Look at This Malicious Campaign Malware loaders have assumed a central role in the cybercriminal ecosystem. These loaders infiltrate machines and deploy additional payloads while evading detection. The loader used in this campaign is particularly noteworthy for its use of the Go programming language and an innovative technique to deploy the Rhadamanthys stealer. This emphasizes the need for Linux admins and security practitioners to stay updated on emerging attack techniques and constantly improve their defense mechanisms to counter such threats. It is critical to highlight how unsuspecting users are directed to a domain controlled by the attackers, masquerading as PuTTY's homepage. From there, a two-step redirection process leads to downloading a malicious PuTTY executable. This executable initiates the downloading of the Rhadamanthys stealer, which, once executed, poses a significant threat by stealing sensitive information from the compromised system. What Are the Implications of This Threat? How Can I Secure My Systems? The implications of this malvertising campaign are severe for Linux administrators and the broader cybersecurity community. The attackers' ability to exploit the trust in widely used tools like PuTTY highlights the need for constant vigilance and scrutiny of sources. It prompts questions about the potential for similar attacks targeting other open-source software that forms the backbone of various operating systems. The use of the Go programming language for theloader is notable as it indicates cybercriminals' evolving sophistication. This poses a challenge for security practitioners who must stay updated on the latest programming languages and techniques attackers employ. Moreover, this threat raises concerns about the long-term consequences of such attacks. As malware and cybercrime evolve and adapt, security practitioners must remain proactive and agile in defending against emerging threats. This includes implementing robust monitoring and detection systems, regularly updating software and firmware, and educating users and administrators about the risks posed by malicious campaigns. The impact on Linux administrators and infosec professionals is profound. They are at the forefront of defending against such attacks and must be aware of the latest techniques employed by cybercriminals. This discovery serves as a reminder that even seemingly legitimate tools and websites can be compromised, underscoring the importance of scrutinizing domain names and sources. Our Final Thoughts on Securing Linux Systems Against Malvertising Campaigns This article highlights the evolving tactics employed by cybercriminals to exploit trust and infiltrate systems. Linux admins, infosec professionals, and sysadmins must stay informed, adapt their defenses, and emphasize the importance of user education to protect against these threats. The consequences of these attacks are far-reaching, making constant vigilance and proactive defense strategies vital to safeguarding critical systems and data. Stay safe out there, Linux admins! . A recent malvertising campaign exploiting PuTTY highlights the risks of popular software. Users should be vigilant, verify downloads, and strengthen security practices. Linux Security, Cybercrime Alert, Malware Defense, Open Source Threats, User Education. . Dave Wreski
Google has abruptly pulled over 500 Chrome extensions from its Web Store that researchers discovered were stealing browsing data and executing click fraud and malvertising after installing themselves on the computers of millions of users. . Depending on which way you look at it, that’s either a good result because they’re no longer free to infect users, or an example of how easy it is for malicious extensions to sneak on the Web Store and stay there for years without Google noticing. That they were noticed at all is thanks to researcher Jamila Kaya who used Duo Security’s CRXcavator tool (also available at CRXcavator.io ) to spot a handful of extensions that seemed suspicious, mostly themed around marketing and advertising. The link for this article located at Naked Security is no longer available. . Microsoft has dismantled more than 300 harmful Edge add-ons found to be capturing personal information and carrying out scams.. Chrome Extensions, Malware Removal, Data Theft Solutions, Cybersecurity Insights, Web Store Security. . LinuxSecurity.com Team
Did you know that Linux is the least targeted OS by malicious ads, accounting for only 0.3% of all malicious ads recorded in a recent study? Most malvertising campaigns (malicious ads) target Windows users,according to statisticsshared last week by cyber-security firm Devcon.Chrome OS is the second most targeted, while Linux is the least. Learn more: . The company said that based on data gathered by its internal tools, 61% of the malicious ads they've observed from between July 11 and November 22, 2019 were aimed at Windows users. This included malicious ad campaigns "designed to redirect the user to malicious sites or to trick the user into downloading a piece of malware." The link for this article located at ZDNet is no longer available. . Research reveals that 59% of harmful advertisements are aimed at Windows operating system users, whereas threats targeting Linux make up a mere 0.4% of the total documented dangers.. Malicious Ads, Cyber Threats, Ad Campaigns, Linux Security, Windows Vulnerabilities. . Brittany Day
If you’re a WordPress admin using a plug-in called Rich Reviews, you’ll want to uninstall it. Now. Learn more: . The now-defunct plug-in has a major vulnerability that allows malvertisers to infect sites running WordPress and redirect visitors to other sites. Rich Reviews is a WordPress plugin that lets sites manage reviews internally in WordPress, and also displays Google display reviews for a business underneath a search result. Marketing company Nuanced Media released it in conjunction with plug-in developer Foxy Technology in January 2013. The honeymoon didn’t last long, though. Updating an oldblog postearlier this month, Nuanced Media reaffirmed that it had discontinued the plugin. It blamed a change in Google’s schema guidelines that stopped merchants displaying review star ratings on their own URLs. The link for this article located at Naked Security is no longer available. . Uncover the critical vulnerability in the obsolete Rich Reviews extension that leaves WordPress installations vulnerable to malicious software.. WordPress Security, Malvertising Risks, Plugin Vulnerabilities, Cyber Attack Prevention. . Brittany Day
The takeover of the SourceForge account for the Windows version of the open-source GIMP image editing tool reported by Ars last week is hardly the first case of the once-pioneering software repository attempting to cash in on open-source projects that have gone inactive or have actually attempted to shut down their SourceForge accounts. . Over the past few years, SourceForge (launched by VA Linux Systems in 1999 and now owned by the tech job site company previously known as Dice) has made it a business practice to turn abandoned or inactive projects into platforms for distribution of "bundle-ware" installers.. In recent times, GitHub has shifted its attention towards capitalizing on dormant open-source initiatives via deceptive advertising tactics.. SourceForge Schemes, GIMP Malvertising, Open Source Practices, Inactive Project Exploitation. . LinuxSecurity.com Team
A new variety of Ransomware has been discovered by Trojan7Malware researchers. Dubbed as OphionLocker, this Ransomware is very unique in the sense that it uses elliptic curve cryptography for file encryption, and Tor for communication. Another unique signature of OphionLocker is that it uses malvertising campaigns to propagate itself rather then traditional spear phishing methods.. Elliptic Curve Cryptography Elliptic curve cryptography (ECC) is a public-key cryptography based on the algebraic structure of elliptic curves over finite fields. One of the main benefits ECC cryptography is that it provides same level of encryption with smaller size of keys. The link for this article located at TechWorm is no longer available. . Elliptic Curve Cryptography Elliptic curve cryptography (ECC) is a public-key cryptography based on . variety, ransomware, trojan7malware, researchers, dubbed, ophionlocke. . LinuxSecurity.com Team
Cybercrooks have brewed a strain of ransomware that uses elliptic curve cryptography for file encryption, and Tor for communication. The malware, dubbed OphionLocker, is spreading using a malicious advertising (malvertising) campaign featuring the RIG exploit kit.. The ransomware encrypts files of particular types on infected systems before using Tor2web URL as a conduit for instructions on how to send the payment and obtain the decryptor tool. The extortionists are asking for a payoff of 1 BTC ($352 at current rates of exchange). The link for this article located at The Register UK is no longer available. . Malware zeroes in on key data, utilizing asymmetric encryption and anonymous networks for demands through digital currency transactions.. Next Gen Ransomware, Cyber Extortion, Malicious Ads, Bitcoin Payments. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.