Tuesday, March 21, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

PlugX malware hides on USB sticks and infects Windows

Kiratas by Kiratas
January 31, 2023
in World
Reading Time: 2 mins read
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

For security reasons, it is better not to connect a USB stick found on the street to your own computer. Security researchers from Unit 42 (Palo Alto Networks) have now confirmed this again when they came across the USB stick infecting malware PlugX.

Well-known Trojan

If PlugX spreads on a Windows PC, it should automatically attack connected USB data carriers and thus pave the way for other computers. According to the researchers’ report, the malware has been around for more than a decade and is said to have been used in cyber attacks on the US government in 2015, among other things.

Now PlugX has reappeared in two variants. The aim of the Trojan is to execute malicious code via DLL side loading with actually legitimate applications. The second variant is designed to copy PDF and Word documents.

In order to infect systems, PlugX is supposed to hijack trustworthy and digitally signed software. In the current case, this should be done using the open source debugging tool for Windows x64dbg. The malware is said to hook itself into the DLL loading process with the maliciously coded X32bridge.dat file. At the moment, only nine out of 60 scanners are said to start with the online analysis service VirusTotal.

In stealth mode

After infection, the Trojan should infect and hide on connected USB data carriers for further spread. Among other things, the malware uses hidden folders that Windows does not display by default.

The campaign’s masterminds use another camouflage trick: They use certain Unicode characters that prevent Windows Explorer from displaying the data on the USB stick, even if you activate the option to show hidden files in Windows .

The only thing victims see on the stick is a shortcut to the malware called TESTDRIVE and their own data stored on the stick. The researchers explain that the complete data structure only becomes visible with a Unix system.

With the automatic malware installation on connected USB data carriers, PlugX could also sneak into systems that are separated from the Internet (air gap) in critical infrastructures.

(of the)

To home page

Tags: hidesinfectsMalwarePlugXSecuritysticksTrojanUSBUSB StickWindows

Related Posts

World

Say goodbye to mess with your spices thanks to Zara Home: the cleanest kitchen ever

by Kiratas
March 21, 2023
World

Crazy: this is how we define the new tableware from Maisons du Monde

by Kiratas
March 21, 2023
World

Java Development: Livestream from the JavaLand conference

by Kiratas
March 21, 2023
World

Vox motion of no confidence against Pedro Sánchez, live | Speech by Ramón Tamames and replicas

by Kiratas
March 21, 2023
World

iX workshop: IT security according to ISO 27001 (with early bird discount)

by Kiratas
March 21, 2023
Next Post

Chris Evans and Ana de Armas together again on the 'Ghosted' poster

Hacker authority: Faeser wants to upgrade Zitis to a monitoring center

The euro area moves away from the risk of recession: it grows 3.5% in 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank Barcelona business ChatGPT Check Cybercrime data data protection day Energy EU euros Facebook February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Spain Spanish Sánchez Test time today Vulnerabilities year years

Recent Posts

  • Credit Suisse bailout forces ECB to calm debt market
  • Say goodbye to mess with your spices thanks to Zara Home: the cleanest kitchen ever
  • Crazy: this is how we define the new tableware from Maisons du Monde
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.