{"id":303122,"date":"2022-10-15T16:42:15","date_gmt":"2022-10-15T11:12:15","guid":{"rendered":"https:\/\/nagalandpost.com\/?p=303122"},"modified":"2022-10-15T16:42:17","modified_gmt":"2022-10-15T11:12:17","slug":"ransomware-campaign-targeting-users-via-fake-windows-10-antivirus-update","status":"publish","type":"post","link":"https:\/\/nagalandpost.net\/index.php\/2022\/10\/15\/ransomware-campaign-targeting-users-via-fake-windows-10-antivirus-update\/","title":{"rendered":"Ransomware campaign targeting users via fake Windows 10, antivirus update"},"content":{"rendered":"\n<p>A ransomware campaign is targeting home users by masquerading as software updates via fake Windows 10 and antivirus installs, cyber-security researchers have revealed.<\/p>\n\n\n\n<p>The ransomware campaign called Magniber is then demanding $2,500 from victims for unlocking their data, reveals HP threat research team.<\/p>\n\n\n\n<p>&#8220;Notably, the attackers used clever techniques to evade detection, such as running the ransomware in memory, bypassing User Account Control (UAC) in Windows, and bypassing detection techniques that monitor user-mode hooks by using syscalls instead of standard Windows API libraries,&#8221; the team explained.<\/p>\n\n\n\n<p>Even though Magniber does not fall into the category of &#8216;Big Game Hunting&#8217;, it can still cause significant damage.<\/p>\n\n\n\n<p>&#8220;Home users were the likely target of this malware based on the supported operating system versions and UAC bypass. The attackers used clever techniques to evade protection and detection mechanisms,&#8221; the security researchers noted.<\/p>\n\n\n\n<p>With the UAC bypass, the malware deletes the infected system&#8217;s shadow copy files and disables backup and recovery features, preventing the victim from recovering their data using Windows tools.<\/p>\n\n\n\n<p>The infection chain starts with a web download from an attacker-controlled website.<\/p>\n\n\n\n<p>The user is asked to download a ZIP file containing a JavaScript file that purports to be an important antivirus or Windows 10 software update.<\/p>\n\n\n\n<p>Home users can protect themselves from ransomware campaigns like this one by following this simple advice:<\/p>\n\n\n\n<p>The HP security team said that home users should only download software updates from trusted sources as the campaign depends on tricking people into opening fake software updates.<\/p>\n\n\n\n<p>&#8220;Back up your data regularly. Backing up your data will give you peace of mind should the worst happen,&#8221; they suggested.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A ransomware campaign is targeting home users by masquerading as software updates via fake Windows 10 and antivirus installs, cyber-security researchers have revealed. The ransomware campaign called Magniber is then demanding $2,500 from victims for unlocking their data, reveals HP threat research team. &#8220;Notably, the attackers used clever techniques to evade detection, such as running [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":303126,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-303122","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-infotainment"],"_links":{"self":[{"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/posts\/303122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/comments?post=303122"}],"version-history":[{"count":0,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/posts\/303122\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/media\/303126"}],"wp:attachment":[{"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/media?parent=303122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/categories?post=303122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nagalandpost.net\/index.php\/wp-json\/wp\/v2\/tags?post=303122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}