Connect with us

Technology

Fake software fixes fuel money-stealing malware threat

Published

on

Fake software fixes fuel money-stealing malware threat

Online protection firm Proofpoint warns that new and sophisticated malware that impersonates Google Chrome and Microsoft has the potential to steal money from Windows device owners. Multiple groups of cybercriminals are using this malware, including some known for sending spam emails that can infect computers with malware or ransomware.

The malware poses as fake updates in internet browsers like Chrome to trick users into downloading harmful code. Once the code is on the computer, the hackers can access cryptocurrencies, sensitive files and personal information.

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Microsoft laptops (Microsoft) (Kurt “CyberGuy” Knutsson)

Advertisement

How does the fake update malware work?

Proofpoint identified a larger distribution of the malware this month, but the online protection firm believes the campaign has been ongoing since March 2024. The malware poses as fake Google Chrome, Word and OneDrive errors to coerce users into downloading harmful code. These errors prompt the visitor to click a button to copy a PowerShell “fix” into the clipboard, then paste and run it in a Run dialog or PowerShell prompt.

“Although the attack chain requires significant user interaction to be successful, the social engineering is clever enough to present someone with what looks like a real problem and solution simultaneously, which may prompt a user to take action without considering the risk,” warns Proofpoint.

When the PowerShell script runs, it checks if the device is a valid target. Then, it downloads more payloads. These steps include clearing the DNS cache, removing clipboard content, showing a fake message, and downloading another remote PowerShell script.

Fake software fixes fuel money-stealing malware threat

ClickFix error message (Proofpoint) (Kurt “CyberGuy” Knutsson)

BEST ANTIVIRUS FOR PCS, MACS, IPHONES AND ANDROIDS – CYBERGUY PICKS

Cryptocurrency theft

This second script checks if it’s running on a virtual machine before downloading an info stealer. Once everything is ready, the hacker can access the victim’s cryptocurrency. This scheme redirects the victim’s funds to the hacker instead of the intended recipient.

Advertisement

Alternative attack method: Email lure

Proofpoint notes that bad actors also use another method called “email lure” to install harmful software. Emails, typically those that appear to be work- or corporate-related, contain an HTML file that resembles Microsoft Word. These emails prompt users to install the “Word Online” extension to view the document correctly.

Similar to the method above, users are prompted to open PowerShell and copy over malicious code. Proofpoint says the deceptive “campaign” is widespread. “The campaign included over 100,000 messages and targeted thousands of organizations globally,” according to the firm.

Fake software fixes fuel money-stealing malware threat

HTML attachment containing instructions on how to copy and paste PowerShell that leads to the installation of malware (Proofpoint) (Kurt “CyberGuy” Knutsson)

DON’T LET SNOOPS NEARBY LISTEN TO YOUR VOICEMAIL WITH THIS QUICK TIP

5 ways to protect yourself from harmful software

The fake Chrome and Microsoft Word malware creates a sense of urgency, making users click on the links and unknowingly compromise their devices. There are several steps you can take to protect yourself from such malware.

1) Have strong antivirus software: The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.

Advertisement

2) Use a VPN: Consider using a VPN to protect against being tracked and to identify your potential location on websites that you visit. Many sites can read your IP address and, depending on their privacy settings, may display the city from which you are corresponding. A VPN will disguise your IP address to show an alternate location. For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices.

3) Monitor your accounts: Regularly review your bank statements, credit card statements and other financial accounts for any unauthorized activity. If you notice any suspicious transactions, report them immediately to your bank or credit card company.

4) Place a fraud alert: Contact one of the three major credit reporting agencies (Equifax, Experian or TransUnion) and request a fraud alert to be placed on your credit file. This will make it more difficult for identity thieves to open new accounts in your name without verification.

5) Enable two-factor authentication: Enable two-factor authentication whenever possible. This adds an extra layer of security by requiring a second form of verification, such as a code sent to your phone, in addition to your password.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET

Advertisement

Kurt’s key takeaways

Hackers have cleverly designed malware that prompts you to install it on your devices. This malware specifically targets Windows users, and I’ve noticed that Windows devices seem to be more susceptible to these kinds of attacks. Recently, Microsoft admitted to a Wi-Fi driver flaw in Windows that allows hackers to hijack your PC simply by being on the same Wi-Fi network. It’s crucial to be cautious when browsing online or connecting to public Wi-Fi.

How do you verify the authenticity of software before downloading and installing it on your device? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels

Advertisement

 Answers to the most asked CyberGuy questions:

Copyright 2024 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Here’s our best look yet at Samsung’s latest Galaxy Z foldables

Published

on

Here’s our best look yet at Samsung’s latest Galaxy Z foldables

While Samsung is gearing up to officially introduce the latest Galaxy Z foldable smartphones at its Unpacked event on July 10th, a new batch of leaked images have spoiled more of the surprise. The renders of the upcoming Galaxy Z Flip 6 and Z Fold 6 handsets come courtesy of established leaker Evan Blass and WinFuture, which show what colors may be available alongside sharing many similarities with previous leaks from SmartPrix, OnLeaks, and Ice Universe.

The images show a more squared-off design for the Galaxy Z Fold 6, which was also seen in images of a prototype earlier this month. The hinge and bezels surrounding the outer display appear smaller, and black rings can be seen around the rear triple-camera lenses. Leaked specifications shared by Smartprix suggest that might be the only noticeable update to the Z Fold 6’s camera system, however, as it seems to be rocking the exact same setup as its predecessor.

The renders supplied by Blass show two color variants for the Galaxy Z Fold 6: Gray and Navy Blue. The hues are slightly different to the Z Fold 5’s Gray and more vivid blue online exclusives, and the separate batch of leaked images shared by WinFuture (which match those provided by Blass) suggests the Fold 6 will also be available in light Pink.

The latest images of the clamshell-like Galaxy Z Flip 6, meanwhile, are nearly identical to the former Z Flip 5 model. The color options we’ve seen — Blue, Silver, Yellow, and Green — seem to have a more mattified “brushed metal” look, and it appears the rings around the two rear-facing cameras are color-coordinated to match the device. It’s a cute change, and the larger cover screen has thankfully been retained, but the lack of major design adjustments may disappoint Samsung users who are expecting a little more from a generational update.

Both the Galaxy Z Fold 6 and Flip 6 are expected to run new Qualcomm Snapdragon 8 Gen 3 processors. Rumors also suggest the Z Flip 6’s main camera will be bumped to a 50-megapixel resolution from the current 12-megapixel variant, and come with an upgraded 4,000mAh battery instead of the 3,700mAh battery found on the Z Flip 5.

Advertisement

Continue Reading

Technology

Superslick electric beast takes you from city streets to mountain peaks

Published

on

Superslick electric beast takes you from city streets to mountain peaks

Get ready to have your minds blown because Callum is about to unleash a game-changer in the automotive world. Forget about your run-of-the-mill sports cars. The Callum Skye is here to redefine what it means to have an exhilarating ride.

Imagine a vehicle that’s equal parts rugged and refined, a perfect blend of off-road capabilities and urban sophistication. That’s the Callum Skye for you – a multiterrain vehicle that’s not afraid to get its wheels dirty on the trails while still looking sharp enough to turn heads on city streets.

So, buckle up and get ready for an adventure that’ll have you grinning from ear to ear. The Callum Skye is about to take you on a wild ride, blurring the lines between on-road and off-road thrills.

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Advertisement

What is Callum?

Formed in 2019, Ian Callum co-founded Callum with his design expertise from Ford, TWR and Jaguar. According to the Callum website, it is a “fresh, dynamic British design and engineering house creating and crafting bespoke products and services for our customers and clients.”

8 things that make Callum Skye so unique

Unlike most cars in its class, Skye has the finishing touches that fit right in an urban sprawl as it does rugged terrain. The vehicle, which measures approximately 13 feet, 3 inches in length and 6 feet, 2 inches in width, includes these features:

1. Luxury: An enclosed, refined 2+2 interior that masks its incredible performance

2. Speed: Matching sports car performance with the ability to go from 0-60 in under 4 seconds

Callum Skye exterior

3. Balanced: 50-50 weight distribution between the front and rear of the vehicle

Advertisement

4. Light yet powerful: It’s hard to imagine that with an estimated 247 horsepower, it weighs in at only 2,535 pounds.

aerial of the Skye

5. Multiterrain: All-wheel drive means it can handle different terrains easily.

6. Electric: This all-electric vehicle is powered by a 42kWh battery.

7. Distance: It has an anticipated range of 170 miles.

8. Fast-charging: There is an option for an ultrafast charging battery that gives a full charge in 10 minutes.

Advertisement

CLICK HERE FOR MORE US NEWS

Callum skye exterior 3

AERODYNAMIC ELECTRIC HYPERCAR IS PACKING SOME SERIOUS HORSEPOWER

Callum unveils refined interior for Skye sports car

Ahead of its highly anticipated debut, Callum has provided a glimpse into the interior design of the Skye sports car, revealing a refined and versatile cabin that sets it apart in its category. The Skye’s 2+2 enclosed cabin boasts a sleek, pillar-like center console bridge featuring rotary touchscreen dials, allowing effortless control over the HVAC and other key features. The dashboard exudes a sense of restrained elegance, with a focus on functionality and a centrally positioned touchscreen set to feature Apple CarPlay and Android Auto integration.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET 

Skye interior

An interior view of the Callum Sky (Callum)

Up front, two cosseting sports seats promise a luxurious and supportive driving experience. In the rear, a versatile bench seat suitable for children can be easily removed, transforming the interior into a configurable load space. With access via a hinged tailgate, the generous storage area is designed to accommodate luggage for long weekend getaways, as well as a variety of sports, lifestyle and outdoor pursuit equipment.

Advertisement

callum skye interior 2

An interior view of the Callum Skye (Callum)

WHY SELF-DRIVING CARS ARE ABLE TO COMPLETELY BREAK THE RULES IN THIS CALIFORNIA CITY

How much does the Callum Skye cost?

The Callum Skye is built for the sophisticated adventurer who is looking for a capable, invigorating drive, no matter where they go. Callum is currently taking orders for Skye via its website with prices starting between approximately $101,600 and $139,700. 

GET READY FOR FOLDABLE ELECTRIC CAR THAT MAKES PARKING A BREEZE

Kurt’s key takeaways

For car and tech enthusiasts alike, Callum Skye is the best of both worlds. With a stunning design that sets it apart from its competitors, it handles well on and off the road. It is a fast, fun ride with the ability to power from 0 to 60 in under 4 seconds, yet it is comfortable and functional enough for a daily commute. The fact that it is all-electric and there is an ultrafast charging battery option makes it a competitive buy for those who want the benefits of an electric car without the common pitfalls and frustrations. Whether you want to take a joyride through the backwoods or the grocery store, the Callum Skye sure elevates itself to a class all its own.

Advertisement

Would you drive this brand-new take on a sporty ride? Does the combination of a sports all-terrain vehicle with a luxurious tech and ride experience inspire you? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most asked CyberGuy questions:

Copyright 2024 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading

Technology

Perplexity AI: the answer engine with a lot of question marks

Published

on

Perplexity AI: the answer engine with a lot of question marks

In the coming weeks, Reddit will start blocking most automated bots from accessing its public data. You’ll need to make a licensing deal, like Google and OpenAI have done, to use Reddit content for model training and other commercial purposes. 

While this has technically been Reddit’s policy already, the company is now enforcing it by updating its robots.txt file, a core part of the web that dictates how web crawlers are allowed to access a site. “It’s a signal to those who don’t have an agreement with us that they shouldn’t be accessing Reddit data,” the company’s chief legal officer, Ben Lee, tells me. “It’s also a signal to bad actors that the word ‘allow’ in robots.txt doesn’t mean, and has never meant, that they can use the data however they want.”

Continue Reading

Trending