Jump to content

Cybercriminals deliver malware using fake NordVPN website


sincity

Recommended Posts

The cybercriminals responsible for breaching and utilizing the website of the free video editor VSDC to distribute malware have begun to create fake websites to accomplish the same goal.

Previously the group hacked legitimate websites to use their download links to spread malware but now they have turned to cloning websites to deliver the Win32.Bolik.2 banking Trojan to the devices of unsuspecting users.

The cybercriminals have created a perfect clone of NordVPN's website to trick users into downloading the Win32.Bolik.2 banking Trojan which was discovered by researchers at Doctor Web.

In addition to being an almost exact copy of the company's website, the cloned website even has a valid SSL certificate issued by the open certificate authority Let's Encrypt. This helps the fake website appear more legitimate while also allowing it to bypass browser security checks.

Cloned websites

In a blog post announcing their discovery, Doctor Web's researchers explained what the Win32.Bolik.2 banking Trojan is capable of after being installed on a user's device, saying:

“The Win32.Bolik.2 trojan is an improved version of Win32.Bolik.1 and has qualities of a multicomponent polymorphic file virus. Using this malware, hackers can perform web injections, traffic intercepts, keylogging and steal information from different bank-client systems.”

The cybercriminals behind this malicious campaign are focusing on English-speaking targets and thousands of users have already visited the fake NordVPN website according to the researchers.

Upon visiting the cloned site, users are prompted to download the NordVPN client just as they would be on the legitimate site. To avoid arousing suspicion, the fake site installs the actual VPN client but also leaves the Win32.Bolik.2 banking Trojan on a user's system as well.

As the group's tactics have been successful so far, expect to see other similar cloned sites being utilized to infect user's systems with malware in the future.

  • We've also highlighted the best VPN services of 2019

Via Bleeping Computer

http://feeds.feedburner.com/~r/techradar/digital-home/~4/YwY0ceROHkk
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...