Shortly after WinRAR patched a major security bug in its platform, cybercriminals have resorted to exploiting the bug in unpatched systems for malicious gains.
A good example is the latest attack campaign conducted by the Goldmouse threat group. The APT group is reportedly targeting the Middle East region. According to security 360 Threat Intelligence Center, Goldmouse was observed deploying the nebulous njRAT backdoor.
The big picture
Android devices also targeted - The researchers also detected multiple samples designed to target Android devices. The samples mimicked popular applications such as Microsoft Office.
“Multiple related Android samples with the same C&C (82.137.255.56) are discovered by 360 Threat Intelligence Center as well. Those recent Android backdoors are disguised as commonly used applications such as Android system and Office software update program,” the researchers wrote in their blog.
Once these false ‘Office Update’ APK files are downloaded on the device, attackers use the C2 server to capture details such as GPS Positioning and perform tasks like recording and photographing from the device.
Publisher