This evil dropper infects you with a dozen malware strains at the same time
Date:
Wed, 28 Sep 2022 20:03:16 +0000
Description:
NullMixer seems to be a demonstration of force, experts warn.
FULL STORY ======================================================================
Cybercriminals have been observed using SEO poisoning to distribute a new malware loader which tries to infect the target endpoint with a dozen malware families.
Researchers from Kaspersky discovered that for many people, typing the
keyword software crack into Google brings up multiple websites distributing this new malware loader, some of which have even made it to the famed first page of the search results. The loader in question is called NullMixer, and
is designed for the Windows operating system and apparently, it installs all kinds of password stealers, viruses, backdoors, banking trojans, crypto miners, you name it. The only thing seemingly missing is ransomware .
Among the malware families installed this way are Redline Stealer, Danabot, Raccoon Stealer, Vidar Stealer, SmokeLoader, PrivateLoader, ColdStealer, Fabookie, PseudoManuscrypt, and others. Baiting with cracks
The attackers chose software crack as their main keyword, researchers
believe, due to the fact that people looking for cracks will usually ignore warnings coming from their antivirus programs and install the executable
files anyway.
According to Kaspersky, NullMixer has so far tried to infect more than 47,000 endpoints protected by its security solutions. The victims were located all over the world, including the U.S., Germany, France, Italy, India, Russia, Brazil, Turkey, and Egypt. Read more
Here's another good reason never to use cracked software
Here's another excellent reason not to pirate your software
These are the best antivirus tools out there
The researchers were also baffled by the number of malware families being installed via NullMixer. Its not exactly subtle. Devices that fall victim to this attack will become significantly slower, have windows popping up for no reason, and will showcase numerous other symptoms of infection. Kaspersky suspects that NullMixer could actually be a demonstration, showing other malware operators what its capable of doing, until one decides to use it for their own distribution efforts.
As things stand now, the best way to eliminate NullMixer from a compromised device is via a Windows reinstall. Check out the best firewalls right now
Via: BleepingComputer
======================================================================
Link to news story:
https://www.techradar.com/news/this-evil-dropper-infects-you-with-a-dozen-malw are-strains-at-the-same-time/
--- Mystic BBS v1.12 A47 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)