Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: Freelance platform users
Incident: A widespread malware campaign utilizing fake freelance profiles to distribute remote access trojans.
Impact: Unauthorized remote access to thousands of computers and the theft of personal and financial data.
Attacker: Searzhudin Tamirlanovich Aktulaev
Analysis: The attacker utilized fake profiles on a freelance platform to distribute Excel macros that deployed TVRAT and DarkVNC. By employing DLL search order hijacking, the malware bypassed basic signature checks to gain remote control of thousands of systems. This highlights the persistent danger of social engineering lures targeting professional networks, a tactic still used by modern state-sponsored actors.
Recommendations: Disable macros by default for all documents received from untrusted external sources.; Implement endpoint detection and response (EDR) to monitor for DLL search order hijacking.; Educate employees on the risks of interacting with unknown recruiters on professional freelance platforms.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source