Fake Anti-virus Software Spreading Malware
Recently, malware disguised as a global vendor’s anti-virus software was discovered. It was found to be spreading via a fake website designed to look like a legitimate site.
The website is a fake website that is almost impossible to tell the difference from the real one to the untrained eye. The sole purpose of the website is to fool users into downloading malware. When a user clicks on the DOWNLOAD NOW button, a malicious file disguised as the company’s anti-virus software file is downloaded.
Once the installation file is executed, two different malware are generated in a temporary path. One additionally generates an .exe file to install and register itself as a service with the name AdobeFlashPlayerHash. It also generates .ini file that is assumed to contain the parameter values for communicating with the C&C server.
Another malware is similar to other cryptocurrency-mining malware. This malware hijacks system resources, such as the CPU and GPU of infected computers, to mine Monery, a cryptocurrency. In addition, this miner, a code for mining virtual currency, includes a kill function for specific processes.
This malware is unique in the sense that once the miner is blocked in the system, the former malware that is registered and continuously executed as a service, will download and execute other miner malware programs from the C&C server.
The attack methods are becoming more varied and sophisticated, for the most common and global problem of phishing and ransomware, and now the relatively new issue of cryptocurrency-mining malware. In order to protect against the changing trends in malware and its variants, personal vigilance is required.