News
NCC warns of phishing attack exploit
The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has warned that a new phishing, attacks exploit windows zero-day vulnerability, can load a malicious QBot malware on the compromised device without triggering any Windows security alerts.
In its advisory, NCC-CSIRT indicated that the vulnerability, which is present in all versions of Windows-based products, presents as Phishing Attacks and Malware threats.
NCC-CSIRT reports that ProxyLife security researcher discovered the new phishing exploit on Windows zero-day vulnerability to drop a Qbot malware without displaying Mark of the Web (MoTW) security warnings.
“To take advantage of the Windows Mark of the Web zero-day vulnerability, threat actors have switched to a new phishing strategy that involves propagating JS files (plain text files that include JavaScript code) signed with forged signatures. The newest phishing attempt begins with an email that contains a password for the file along with a link to an allegedly important document.
“When the link is clicked, a password-protected ZIP folder that includes another zip file and an IMG file is downloaded. Normally, launching the JS file in Windows would result in a Mark of the Web security warning because it is an Internet-based file. However, the forged signature permits the JS script to function and load the malicious QBot program without triggering any Windows security alerts,” the advisory said
-
World News7 days ago
Biden says ‘nobody can reverse’ his climate agenda. But Trump is poised to try.
-
Gist3 days ago
VIDEO: Congo’s president daughter’s bedroom video leaks
-
News5 days ago
NIMASA DG JOB: Gbajabiamila Allegedly Collected $1m Bribe From Victor Ochei, Others Paid $2m, $3m, Tinubu’s Man Akinyelure Fingered, ONI-Okpaku Arrested ___Jackson Ude
-
Politics3 days ago
Patani stands still as High Chief (Dr) Wayles honors his mother, remembering her legacy 5 years later.
-
Business7 days ago
JUST-IN: Auditor-General uncovers N3.4trn fraud
-
Sports2 days ago
Juventus Terminates Paul Pogba’s Contract: What’s Next for the French Midfielder?
-
Crime3 days ago
Alowonle Arrested, Shot In Police Custody – Osun Park Managers
-
News3 days ago
IGP Orders Arrest Of Osun Anti-Kidnapping Squad Leader Over Alleged Attempted Murder