TGViewer
📜 Чтиво 📜 📜 Чтиво 📜 @chtivvvo · 137 subscribers
Post #1450 212
https://www.theregister.com/2023/12/20/credentialstealing_malware_infects_50k_banking/

When the requested banking page "contains a certain keyword and a login button with a specific ID present, new malicious content is injected," Langus explained. "Credential theft is executed by adding event listeners to this button, with an option to steal a one-time password (OTP) token with it."

The script is fairly smart: it communicates with a remote command-and-control (C2) server, and removes itself from the DOM tree – deletes itself from the login page, basically – once it's done its thing, which makes it tricky to detect and analyze.

The malware can perform a series of nefarious actions, and these are based on an "mlink" flag the C2 sends. In total, there are nine different actions that the malware can perform depending on the "mlink" value, we're told.

These include injecting a prompt for the user's phone number or two-factor authentication token, which the miscreants can use with the intercepted username and password to access the victim's bank account and steal their cash.
  • 👍 3
More from @chtivvvo
  1. Dec 3, 2024Novel phishing campaign uses corrupted Word documents to evade security A novel phishing a…
  2. Nov 18, 2024Phishing emails increasingly use SVG attachments to evade detection Threat actors increasi…
  3. Nov 3, 2024https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botn…
  4. Oct 31, 2024https://sharpsec.run/rce-vulnerability-in-qbittorrent/
  5. Oct 11, 2024https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
  6. Oct 9, 2024https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-u…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →