Pause before you install

25 March 2020 Smart Home Automation

Kaspersky researchers have uncovered a new method of distributing malware: under the guise of fake security certificates. When users attempt to enter an infected site, an iframe appears stating the site’s security certificate is out of date and the connection cannot be completed. In order to proceed, it is recommended that they install a new certificate. However, what’s actually installed is malware on the victim’s computer.

So far, two types of Trojans have been downloaded as a result of this type of attack: Mokes and Buerak. The former provides backdoor access to the victim’s device, while the latter downloads additional malware on the infected device.

Backdoors are a very dangerous type of malware. Their functionality allows threat actors to gain control over an infected machine for malicious purposes. At the same time, the user might not even suspect that the machine is being exploited.

Cybercriminals have, in the past, used updates for legitimate applications as a means of spreading malware, but the use of false security certificates is new.

“People are particularly susceptible to this type of attack because it appears on legitimate websites, ones they’ve possibly already visited. What’s more, the address listed in the iframe is, in fact, the real address of the website. The natural instinct then is to ‘install’ the recommended certificate, so they can view the content they want to. However, users should always be wary when prompted to download something by an online source – chances are, it’s not necessary,” says Victoria Vlasova, security expert at Kaspersky.

To avoid downloading potentially harmful malware on your device, Kaspersky experts recommend that you:

• Double-check the format of the URL and the spelling of the company name.

• Manually type the website address in your browser rather than visiting via a link.

• Use a security solution to protect you against a variety of cyber threats.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Wireless home surveillance
Smart Home Automation
EZVIZ has launched its AOV software alongside the X5S large-capacity storage solution, providing a 360-degree security solution with real-time footage of incidents and recorded evidence when needed.

Read more...
Wi-Fi security camera with PIR
Ajax Systems Smart Home Automation
Ajax Systems has introduced the IndoorCam, designed for private households, small offices, and small to medium businesses, equipped with a 4 MP camera, HDR, and IR illumination of up to 8 m.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Kaspersky warns of active Docusign-themed phishing scams
Kaspersky Information Security
Kaspersky is warning of a rising phishing scam involving fraudulent emails pretending to be from Docusign, a globally used e-signature platform, where users are asked to enter a work login and password credentials.

Read more...
Stay safe while using AI assistants
Kaspersky Information Security News & Events AI & Data Analytics
The new DeepSeek AI assistant has attracted a lot of attention, including the interest of cybercriminals. Kaspersky experts have detected scam activity related to it.

Read more...
Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
Know who’s spying on you
Kaspersky Information Security Products & Solutions
According to the latest State of Stalkerware report, 40% of the people surveyed worldwide stated they have experienced stalking or suspect they are being spied on. A solution for Android is now available.

Read more...
Dahua launches 2-wire hybrid video intercom system
Dahua Technology South Africa Smart Home Automation Access Control & Identity Management Residential Estate (Industry)
Dahua Technology has launched a 2-Wire Hybrid Video Intercom System (the Dahua EACH Series) that redefines residential security and communication with its high image quality and easy deployment features.

Read more...
Kaspersky detects over 1 million daily tracking attempts
Kaspersky News & Events Information Security
Kaspersky's latest analysis of the 25 most prevalent web tracking services, including Google services, New Relic and Microsoft, has revealed over 38 billion instances of web trackers collecting user behaviour data in 2024, with an average of one million detections per day.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...