Threat actors are using free or illegal copies of popular software to trick unwary users into downloading a malware loader called Hijack Loader, which then launches an information-stealing program named Vidar Stealer.
In a Monday investigation, Trellix security researcher Ale Houspanossian stated, “Adversaries had managed to trick users into downloading password-protected archive files containing trojanized copies of a Cisco Webex Meetings App (ptService.exe)”.
The Cisco Webex Meetings application secretly loaded a covert malware loader that resulted in the execution of an information-stealing module when unwary victims extracted and ran a “Setup.exe” binary file.
The initial step involves opening a RAR archive file that appears to be an executable named “Setup.exe,” but is actually a duplicate of the ptService module from Cisco Webex Meetings read more about Cybercriminals Exploit Free Software Lures to Deploy Hijack Loader and Vidar Stealer.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
