FakeSG enters the ‘FakeUpdates’ arena to deliver NetSupport RAT

0
[ad_1]

A new campaign leveraging compromised WordPress sites emerges with another fake browser update.

Over 5 years ago, we began tracking a new campaign that we called FakeUpdates (also known as SocGholish) that used compromised websites to trick users into running a fake browser update. Instead, victims would end up infecting their computers with the NetSupport RAT, allowing threat actors to gain remote access and deliver additional payloads. As we have seen over the years, SocGholish is an established player that has managed to compromise countless victims and deliver ransomware after facilitating the installation of tools like Cobalt Strike or Mimikatz.

Now, there is a potential new competitor in the “fake updates” landscape that looks strangely familiar. The new campaign, which we call FakeSG, also relies on hacked WordPress websites to display a custom landing page mimicking the victim’s browser. The threat actors are distributing NetSupport RAT either as a zipped download or via an Internet shortcut. While FakeSG appears to be a newcomer, it uses different layers of obfuscation and delivery techniques that make it a threat to take seriously and which could rival potentially rival with SocGholish.  

Campaign similarities

We first heard of this new campaign thanks to a Mastodon post by Randy McEoin. The tactics, techniques and procedures (TTPs) are very similar to those of SocGholish and it would be easy to think the two are related. In fact, this chain also leads to NetSupport RAT. However, the template source code is quite different and the payload delivery uses different infrastructure. As a result, we decided to call this variant FakeSG.

Original public discovery

Templates

FakeSG has different browser templates depending on which browser the victim is running. The themed “updates” look very professional and are more up to date than its SocGholish counterpart.

Fake Chrome update

Fake Edge update

Fake Firefox update

Website injections

Compromised websites (WordPress appears to be the top target) are injected with a code snippet that replaces the current webpage with the aforementioned fake updates templates. The source code is loaded from one of several domains impersonating Google (google-analytiks[.]com) or Adobe (updateadobeflash[.]website):

Malicious code injected into hacked websites

That code contains all the web elements (images, fonts, text) needed to render the fake browser update page. We should note that SocGholish used to retrieve media files from separate web requests until more recently when it started using self-contained Base64 encoded images.

Source code for Chrome template

Installation flow

There are different installation flows for this campaign, but we will focus on the one that uses a URL shortcut. The decoy installer (Install%20Updater%20(V104.25.151)-stable.url) is an Internet shortcut downloaded from another compromised WordPress site.

Malicious URL shortcutThis shorcut uses the WebDav HTTP protocol extension to retrieve the file launcher-upd.hta from a remote server:

WebDav malicious HTA

This heavily obfuscated script is responsible for the execution of PowerShell that downloads the final malware payload (NetSupport RAT).

Source of malicious HTA file

Malwarebytes’s EDR shows the full attack chain (please click to enlarge):

Killchain viewed by Malwarebytes EDR

The NetSupport RAT files are hosted on the same compromised WordPress site used earlier to download the Internet shortcut. The RAT’s main binary is launched from “C:\Users\%username%\AppData\Roaming\BranScale\client32.exe“.

NetSupport RAT

Following a successful infection, callbacks are made to the RAT’s command and control server at 94.158.247[.]27.

Web traffic from full infection

Roommates

Fake browser updates are a very common decoy used by malware authors. In addition to SocGholish, the Domen toolkit was a well-built framework that emerged in 2019 while another campaign known as sczriptzzbn dropped SolarMarker leading to the NetSupport RAT in both cases. Initial access brokers use tools like NetSupport RAT to gather information and perform additional actions on victims of interest. Stolen credentials can be resold to other threat actors tied to ransomware gangs.

It is interesting to see another contender in this relatively small space. While there is a very large number of vulnerable websites, we already see some that have been injected with multiple different malicious code. From a visitor’s point of view, this means there could be more than one redirect but the “winner” will be the one who is able to execute their malicious JavaScript code first.

We will continue to monitor these campaigns and in particular SocGholish to see if the web delivery landscape changes. Malwarebytes customers are protected as we detect the infrastructure and final payload used in these attacks.

EDR detection

Indicators of Compromise (IOCs)

FakeSG infrastructure

178.159.37[.]73
google-analytiks[.]com
googletagmanagar[.]com
updateadobeflash[.]website

WebDav launcher

206[.]71[.]148[.]110
206[.]71[.]148[.]110/Downloads/launcher-upd[.]hta

NetSupport RAT

pietrangelo[.]it/wp-content/uploads/2014/04/BranScale[.]zip
pietrangelo[.]it/wp-content/uploads/2014/04/client32[.]exe

NetSupport RAT C2

94[.]158[.]247[.]27

MITRE ATT&CK techniques

Tactic ID Name Details
Execution T1059 Command and Scripting Interpreter Powershell used to download payload
T1059.001 Powershell Starts POWERSHELL.EXE for commands execution
T1059.003 Windows Command Shell Starts CMD.EXE for commands execution
Privilege escalation T1548 Abuse Elevation Control Mechanism Encoded PowerShell
T1548.002 Bypass User Account Control  
Defense evasion T1564 Hide Artifacts  Encoded PowerShell
T1218 System Binary Proxy Execution  Drops CMSTP.inf in %temp%
T1027 Obfuscated Files or Information  Drops th5epzxc.cmdline in %temp%
T1112 Modify Registry Adds key to registry: HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\open\command /f /ve /t REG_SZ /d C:\Users\admin\AppData\Roaming\BranScale\client32.exe
T1548 Abuse Elevation Control Mechanism  
T1140 Deobfuscate/Decode Files or Information  Encoded PowerShell
Discovery T1082 System Information Discovery Gets computer name
C&C T1071 Application Layer Protocol NetSupport RAT C2 communication
T1571 Non-Standard Port Port destination: 5051

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Galaxy A52, A52 5G & A52s 5G are widely getting July 2023 update

0
[ad_1]

A couple of mid-range Samsung smartphones are receiving the July 2023 Android security patch. The company has released the latest security update for the Galaxy A52 and Galaxy A52s. The update is rolling out widely for both models, including the 4G and 5G versions of the former.

The July SMR (Security Maintenance Release) for the Galaxy A52 4G comes with the firmware build number A525FXXS6DWG1 in Europe, Asia, and Australia. The rollout has yet to reach Africa and Latin America. It should be the same build number in Africa, but the latter market may get a slightly different one because of the phone’s model number in the region (SM-A525M).

Regardless of the firmware version, the changelog should remain the same. And there isn’t much to talk about that. Samsung confirms that the Galaxy A52 is only getting the latest security fixes and nothing else. It’s the same story for the Galaxy A52 5G as well. Users are getting the update with build numbers A526BXXS4EWG1 (Europe and Latin America) and A526USQSAEWG1 (US carrier-locked units).

Samsung will soon expand the rollout to cover the remaining Galaxy A52 and Galaxy A52 5G units with the July SMR, including the factory-unlocked variants of the latter in the US. Meanwhile, the Galaxy A52s 5G is picking up the latest security update in Europe. The new build number for this phone is A528BXXS4EWG1. The Korean firm didn’t release the device in the US.

If you’re using either of these mid-range Samsung smartphones, the July security patch should be available to you anytime now. Watch out for a notification prompting you to download the OTA (over the air) update in the coming days if you haven’t already received it. Tap on the notification to proceed. You can also manually check for updates from the Settings app. Go to the Software update menu and tap on Download and install.

These Galaxy devices are getting 90 security fixes with the July update

The July 2023 SMR for Galaxy devices is a pretty big one. Samsung is pushing as many as 90 vulnerability patches to its Android-powered phones and tablets this month. These include 38 Galaxy-specific patches and over 50 Android OS fixes, at least three of which are critical ones. The Korean firm will update more eligible Galaxy devices to the July SMR in the coming days. We will keep you posted with those releases as and when they come.


[ad_2]
Source link

Arrow Lake Intel processors might make slimmer laptops possible

0
[ad_1]

Aside from performance improvements, the design of laptops is always getting better. This involves not only looks but how the laptop feels in hand, and reports have it that the coming Arrow Lake Intel processors will help in this regard. While this processor might help laptops using it achieve a level of slimness, it’d also improve performance.

So one can argue that Intel aims to use this processor to achieve two important things. You can use the idiom ‘to kill two birds with one stone’ to perfectly explain Intel’s plan with this processor. According to sources of this information, the Arrow Lake processors will make an appearance sometime next year.

This processor series will succeed the coming Raptor Lake processor that’d launch this year. Yes, the successor to the processor that’d bring super slim laptops is not yet in use. While these processors are to be launched soon, it is still essential to get an idea of what they’d offer.

The coming Arrow Lake Intel processors might stand out in its category

The available performance chart of the coming Arrow Lake Intel processor screams in its favor. It was put up against its to-be predecessor, the Raptor Lake processor. For the test, these processors were put through a series of platforms including Geekbench and one stood out.

In all tests, the coming Arrow Lake processor proves to be better than the Raptor Lake entry. Both processors are yet to launch, but their performances are already out in the open. However, these processors might perform differently, since the chart shows projections of their benchmark performance.

The coming Arrow Lake processor will launch next year and will bring real improvements. This might mean that it’d prompt the release of slim and lightweight laptops. This will be a clear upgrade from what is currently available on the Intel-powered laptop market.

Currently, one of the slimmest Intel laptops on the market is the 2023 LG Gram, measuring 0.43 inches. With the coming Arrow Lake processor from Intel, we might see more of this laptop size. This processor will attract a ton of users in terms of its performance both for work and gaming.

More details on this processor will be made available in the coming months. While Intel preps for the launch of the Arrow Lake processor, the Raptor entry will launch in a few months. This launch will give netizens an idea of what its successor will pack in terms of usage.


[ad_2]
Source link

Microsoft is still investigating how hackers accessed its emails

0
[ad_1]

After Chinese hackers could get access to Microsoft email accounts, the tech giant is still investigating the case to identify holes in its systems. Sources claim hackers had access to the company’s servers for almost a month before getting caught and pushed out.

Last week, Microsoft revealed that some bad actors from China could gain access to over two dozen of their email accounts. The impacted accounts reportedly belonged to some high-profile organizations, including government agencies.

Microsoft’s further investigations revealed that the hacking campaign, dubbed “Storm-0558”, started mid-May this year. And targeted the email accounts of 25 organizations. The company later explained hackers took access to the accounts through Outlook Web Access in Exchange Online (OWA) and Outlook.com by forging authentication tokens to access user email.

Chinese hackers penetrated Microsoft servers and gained access to the US government emails

Microsoft now says the method hackers used to gain server access is still “a matter of ongoing investigation.” According to the company’s explanations, an issue with the Microsoft account consumer signing key (MSA) allowed hackers to compromise the email accounts. The issue has been corrected.

Of course, Microsoft has yet to remain tight-lipped about the scope of damage and the data being stolen. The company added they had contacted the targeted customers to provide them with a proper response. “If you have not been contacted, our investigations indicate that you have not been impacted,” the company said.

Microsoft says nothing to be done by users, and they are taking care of the case to identify the roots. However, some compromised email accounts reportedly belonged to the US government, meaning some highly confidential government information might be taken by Chinese hackers.

Still, there is no clue to confirm Storm-0558’s relationship with the Chinese government. By the way, prior experiences show that most Chinese hacking groups work under government supervision. In recent months, the tensions between the United States and China have reached their peak. Such espionage actions by the Chinese government could add fuel to the fire of tensions between countries.


[ad_2]
Source link

Beware! Scammers are everywhere, even on Google Maps

0
[ad_1]

Google Maps has matured into an extremely useful app that does much more than just help you navigate quickly, but safely, from point “A” to point “B.” And once you get to point “B,” Google Maps will tell you where to dine, where to shop, where to find entertainment, and where to get a good night’s sleep. The app will also give you the phone number to call when you want to get in touch with a business-like an airline.

Scammers submit fake business numbers to Google Maps to scam users

According to a tweet from UX designer Shmuli Evers (via AndroidPolice), it appears as though scammers are replacing the legitimate hotline numbers on Google Maps with their own phone numbers. As Evers relates, his flight on Delta Airlines was canceled. When it became obvious that Delta’s customer service number was swamped, he looked up a hotline number on Google Maps. When the party answered on the other side, Evers started to explain that his flight was canceled and he needed a new flight.

The call got disconnected and then Evers’ phone rang; he was called from a French phone number and Caller ID showed the name of a person unrelated to Delta Airlines. The person then identified themselves as an airline representative. Shmuli gave his name and the confirmation number of his new flight. He was then directed by the “airline representative” to send the confirmation number of the new flight to another number via SMS. He also was asked to pay for the new flight reservations up front.

Worried that he was the entree in a scam meal, Evers hung up the call only to get bombarded by text asking him to pay five times the price of his original ticket to re-book. It turns out that the phone number from Google Maps that Evers originally called was connected to Delta’s local help desk at John F. Kennedy Airport. He also did some gumshoe work and found wrong numbers for American Airlines in Google Maps. Both numbers have since been corrected. A lot of information found in Google Maps is crowdsourced such as the hours of operation for a business, and hotline numbers.
What might have happened to Evers is that the information he would have texted to the “airline representative,” including the confirmation number for his “paid” replacement flight, would have been used by the scammer or one of his/her operatives to pick up the ticket at the airport where it might have been cashed in, sold, or used. Fake businesses are also popping up on Google Maps including scam locksmiths. Scammers are also calling small businesses saying that they are from Google and will remove their Google Maps listing unless they pay up to cover an ‘unpaid bill.”

A fake call from Verizon

Google could stop crowdsourcing information and leave it to businesses to provide information for Maps, but since many businesses don’t want to deal with providing Google with this data, Maps would lose the ability to provide information about many businesses. So instead, Google continues to receive crowdsourced data.

You could get confronted at any time by a scammer. As I wrote this article, my phone rang and the voice on the other end of the line claimed to belong to a Verizon representative. “How are you doing tonight?” the caller said. Realizing that it was a taped scam call, I responded that my night was not going well and that a safe had fallen on my head from a window above me. “Glad to hear that,” said the voice in a cheerful manner. I hung up. 

Had I continued on the call, I probably would have been asked for some personal information designed to hijack my Verizon account which would have been used to order pricey new iPhone models.

As Shmili Evers discovered, scammers are everywhere. Trust your gut. If something seems odd and doesn’t make sense, you’re probably being scammed.


[ad_2]
Source link

Samsung at the top as smartphone sales dropped 8% in Q2 2023

0
[ad_1]

Smartphone sales continue to tumble globally. According to research firm Counterpoint, smartphone shipments were down eight percent year-on-year (YoY) and five percent quarter-on-quarter (QoQ) in Q2 2023. This was the eighth consecutive quarter to see a YoY decline. Samsung is still at the top but it suffered a bigger drop in sales than some of its rivals.

Counterpoint’s study revealed that Samsung captured 22 percent of the global smartphone market this past quarter. The figure is unchanged from the same period last year. The Korean firm benefitted from strong sales of its Galaxy A series mid-range devices globally, the research firm states. Samsung launched the Galaxy A54 5G and Galaxy A34 5G in late March.

Samsung may still be in danger

It’s not all sunshine and roses for the world’s largest smartphone vendor, though. Samsung’s smartphone shipments dropped 12 percent YoY in Q2 2023. That’s worse than the global average of eight percent. Worse yet, its closest rival Apple only saw a two percent YoY decline in iPhone shipments during the same period. This helped the company increase its share by a percentage point to 17 percent.

This was Apple’s highest-ever Q2 market share, which is notable because the second quarter is usually an unfavorable season for the iPhone maker. It also posted its highest-ever Q1 share earlier this year. Slowly but surely, Apple is threatening to topple Samsung as the global smartphone king. The Korean firm has topped this chart for the past several years, even though Apple often leapfrogs it in the final quarter of the year.

Xiaomi (12 percent market share), Oppo (10 percent), and Vivo (8 percent) are the next three biggest smartphone companies. The former saw a 12 percent YoY decline in shipments as it struggled in its two primary markets — China and India. Vivo also faced similar headwinds in its major markets, leading to a 17 percent YoY decline. It was the worst-hit company among the top five.

Oppo, on the other hand, is reaping the benefits of taking OnePlus in-house. This has helped the company grow in India and China, though it registered losses in European markets. Overall, its smartphone shipments were down only three percent YoY in the second quarter of the year. The fourth-placed Oppo has distanced itself a little from the fifth-placed Vivo and moved closer to the third-placed Xiaomi.

“The global smartphone market now seems to be well past its rapid growth phase, with consumer replacement cycles getting longer, convergence in device innovation, and the emergence of a more mature refurbished market for smartphones hitting particularly the higher-volume low-to-mid-tier price segment demand,” wrote Counterpoint Research analyst Ankit Malhotra.

Counterpoint Global smartphone market share Q2 2023


[ad_2]
Source link

Factory Production of Ulefone Armor 21 Revealed In New Video

0
[ad_1]

The Armor 21 with an infinite halo design has gained much popularity for Ulefone. And the official social media of Ulefone, such as TikTok has received quite a few new followers. From processes from the official launch, pre-sales, official sales to production, Ulefone will update all those information for their users and fans. Therefore, Ulefone has released a video of the mass production of the Armor 21 for the public.

How Ulefone Armor 21 Is Made in the Factory

In their self-owned factory, Ulefone has complete production equipment, production process, and fully compliant with ISO-9001 standard. Their plant is claimed to cover an area of 10,000 square meters, which boasts the leading productivity in the industry.

In the first half of the video, it shows parts assembly of Armor 21. Before assembling, the IQC workers will conduct stringent quality control of the materials and distribute it to the assembly line workers as claimed. Then it comes to the back shell assembling, and the workers carefully assemble the motherboards, battery, card slots, cameras, power supplies and other components. All these steps, especially dispensing is done manual, which requires careful attention and high precision

Move on to the next half of the video, it tells the various testing of the smartphones. The workers are testing the keys sensitivity, contacts, accuracy, air-tight performance, touch screen, operating system, camera replacement, induction, earphones, calls, etc. on the phones once the mobile phone has been assembled.

Besides that, Ulefone has the last process of quality control. Ulefone reliable quality is ensured by the stringent durability tests done for the Armor 21. Including touch screen tests, USB plug-in stress tests, pressing tests, bend tests, micro drop tests, multi-angle drop tests, high/low-temperature tests, dust tests, tumble tests, and much more. Those series of durability tests confess the solidness and toughness of Armor 21.

Ulefone Armor 21 Specs

  • IP68/IP69K, MIL-STD-810H proof, 1.5m waterproof, 1.5m drop resistance, 1m concrete deep, can endure extreme weather and harsh environment;
  • Featured with Infinite Halo, RGB light effects for music, notification and much more;
  • 122dB Halo speaker, HiFi quality loudest speaker with 3.5W peak wattage and 122dB max loudness;
  • With uSmart Expansion Connector for more playability and professional extended devices;
  • IR Blaster feature can turn Armor 22 into a universal remote for air conditioner and other home appliances;
  • 6.58″ FHD+ 120Hz display, large screen with stunning colors and sweeping visuals, fluid multitasking and gaming is allowed;
  • 9600mAh battery, huge capacity without power anxiety to endure for several days;
  • MediaTek Helio G99, 6nm process, extremely fluid and smooth experience;
  • Up to 16GB RAM, enhancing working efficiency;
  • Android 13, users have more control for notification permission and media access, more private, secure and personalized operating system;
  • 64MP Main Camera, Sony IMX686 wide sensor, lighter and more clear and detailed images
  • 24MP Night Vision Camera, clearer images with better algorithm and lower interference;
  • Dock Charging Feature, Armor 21 supports dock charging for much more convenience in daily life;
  • Supports NFC + Google Pay, and offers a convenient and secure way for mobile payment, identification, and authentication such as ID cards or passports, bus ticketing, etc.

[ad_2]
Source link

Galaxy Watch 6 specs leak, showing screen size, battery capacity

0
[ad_1]

The specs of the Galaxy Watch 6 have leaked, showcasing a list of details about the upcoming smartwatch from Samsung. The leak, coming from SnoopyTech on Twitter, seems to confirm most of the watch’s key details. Including screen size, battery capacity, weight, colors and more.

Samsung is expected to officially unveil the Galaxy Watch 6 at its upcoming mid-year Unpacked event happening Seoul, South Korea. Alongside the watch, Samsung is also rumored to reveal its next set of flagship phones, as well as new tablets and some new earbuds. According to the leaked specs sheet, the Galaxy Watch 6 will be 28% lighter than the Galaxy Watch 5 Pro. But it’ll be 40% lighter than the Galaxy Watch 6 Classic.

It’s also rumored to have a 300mAh battery 40mm size and a 425mAh battery in the 44mm size. Both the Galaxy Watch 6 Galaxy Watch 6 Classic will run on Wear OS powered by Samsung. And it looks like both watches will use a Sapphire glass for the display.

Leaked Galaxy Watch 6 specs confirm chipset, RAM, and storage

Much and more has leaked about the Galaxy Watch 6 and Galaxy Watch 6 Classic. To the point that there is almost going to be nothing left to the imagination once Samsung announces both watches. This now includes key specs like the RAM and storage, as well as the chipset Samsung is using to power the computing.

According to Snoopy Tech, both the Galaxy Watch 6 and Galaxy Watch 6 Classic will run on Samsung’s own Exynos W930 chip. And each watch will come with 2GB of RAM as well as 16GB of internal storage. More than enough for anything you might need to do with a smartwatch. Whether that be install apps or download music for offline playback.

New this year it looks like Samsung is implementing some improved sleep features. Sleep tracking and improved sleep has been a focus of Samsung’s Galaxy Watch lineup of late. And this year the Galaxy Watch 6 and Galaxy Watch 6 Classic will “analyze and measure your sleep down to the smallest detail to give you tailored recommendations and tips on how to sleep better.” It’s not clear exactly how the new watch will accomplish this. But more will surely come to light after Samsung officially announces the device.

Additionally, the leak contains other information like colors of each watch. Which include Graphite Gray, Gold, and Silver for the Galaxy Watch 6, and Black and Silver for the Galaxy Watch 6 Classic.


[ad_2]
Source link

Samsung’s wireless speakers are no longer boot looping

0
[ad_1]

Not too long ago, people using the WAM speakers from Samsung’s “R” series experienced an annoying issue. They were boot looping, and there wasn’t really a way to make it stop. However, Samsung fixed the boot looping issue with its speakers, according to SamMobile.

We’re not sure what the issue with the speakers was. However, devices like the R1, R Lite, R3, and R6 experienced this problem. While this issue was a mystery, there was a workaround. Users could still use the speakers if they disconnected them from the internet. While this gave them their speakers back, it was annoying having to disable a core feature.

However, Samsung fixed the boot looping issue with its speakers

This issue caught the attention of Samsung, and the company was able to patch it up. Samsung told its users that the speakers are now working again. The company encouraged its users to reconnect to the internet. While the company didn’t go into too much detail about what caused the problem, it said that it was “resolved by an update to our third-party content providers server.”

That’s good news for people who want to enjoy their music using their WAM speakers. If you experienced this issue, you should be good to reconnect it to the internet.

Other Samsung news: Here are leaked specs of the Galaxy Watch 6

If you’re waiting for the next Galaxy Watch, then we have some leaked specs for you. This smartwatch is set to get an unveiling this month. Rumor has it that the Galaxy Watch 6 will have a 300mAh battery in the 40mm size and a larger 425mAh battery in the 44mm size.

This watch could use the Exynos W930 SoC. That could be backed up by 2GB of RAM and 16GB of storage. There’s a lot more information about this phone, so, if you’re interested in reading more, you can check out the story here.


[ad_2]
Source link