The Operators of Fiesta Exploit Kit Have Switched the Payload Delivered to Users with Outdated Browser Plugins from Crypto-Malware to Fake Antivirus Software, an Old Type of Threat that Runs a Bogus Scan and Tricks Users into Purchasing the Product to Get Rid of the Infections.
The Counterfeit Product is Promoted as "Antivirus Pro 2015" and it Disables Some Windows Tools and Software that Could be Used to Deactivate it, such as Task Manager, Process Explorer and Internet Explorer. Researchers at Trend Micro Found that, the New Payload Started to be Distributed after March 19, a Switch from Spreading Crypto-Malware, TeslaCrypt, that Deletes Shadow Copies and Encrypts Mostly Files Used by Popular Game Titles.
Among the Games Affected by TeslaCrypt, there are Call of Duty, StarCraft 2, MineCraft, Half-Life 2, The Elder Scrolls (Skyrim-Related Files), WarCraft 3, Assassin’s Creed, World of WarCraft, League of Legends and World of Tanks.
The Reason for Changing the Payload to Antivirus Pro 2015 is Not Known but, Exploit Kits are Often Employed for Dispensing Different Threats.
According to Telemetry Data from Trend Micro, the Country Most Targeted by Fiesta Operators during the Month of March is the United States, Accounting for More than a 3rd (36.9%) of the Total Infections Recorded. The Next 2 Countries Impacted are Japan (15.73%) and Australia (11.9%). Antivirus Pro 2015 Relies on Scareware Tactics and Displays Multiple Security Warnings to the Victim, Promising to Clean the System of All Alleged Threats if a 1 or 3-Year License of the Product is Purchased (Some Versions of the Threat Ask for at least $64 / €60).
On the Online Payment Page, Users Have to Provide the Card Data, which May be Collected for Fraudulent Purchases in the Future.
The False Anti-Malware Program is Detected by Multiple Genuine Antivirus Products, including the Free Versions and the General Recommendation is to Have them Up-to-Date.
Fiesta Browser-Based Attack Tool includes Vulnerabilities for Outdated Versions of Adobe Flash Player, Internet Explorer, Silverlight and Adobe Reader. Having the Latest Versions of these Products Installed is a Good Way to Protect against Drive-by Attacks.
quarta-feira, 29 de abril de 2015
Fake Antivirus Delivered to Users in the US via Fiesta Exploit Kit
14:59
No comments
0 comentários:
Enviar um comentário