Hackers Use Weaponized JPEG File to Deploy Trojanized ScreenConnect Malware

https://cybersecuritynews.com/hackers-use-weaponized-jpeg-file/

50 points · 4 comments · view on lemmy.world

4 Comments

NickeeCoco@piefed.social · 16 pts · 119d (1 reply)

The embedded PowerShell code creates a hidden folder at C:\Systems and downloads a trojanized ScreenConnect package from legitserver.theworkpc[.]com over TCP port 5443.

Nothing to see here, just a legit server doing work with the systems.

blargh513@sh.itjust.works · 1 pts · 119d

URL appears to be dead. Tried to pull a copy of that zip file, just times out.

sudoMakeUser@sh.itjust.works · 15 pts · 119d

You wouldn't download a weaponized jpeg

Anon518@sh.itjust.works · 6 pts · 119d

Security teams are advised to block or closely monitor execution of commonly abused Windows binaries including csc.exe, cvtres.exe, and ComputerDefaults.exe. Organizations should enforce strict controls over remote access platforms, deploy detection rules for suspicious PowerShell behavior, and isolate any system showing unexpected ScreenConnect activity. Credential resets for all privileged accounts are strongly recommended following any suspected exposure.

So all windows users without a "security team" are vulnerable to this extremely simple & powerful attack for the foreseeable future???