Pause before you install

25 March 2020 Smart Home Automation

Kaspersky researchers have uncovered a new method of distributing malware: under the guise of fake security certificates. When users attempt to enter an infected site, an iframe appears stating the site’s security certificate is out of date and the connection cannot be completed. In order to proceed, it is recommended that they install a new certificate. However, what’s actually installed is malware on the victim’s computer.

So far, two types of Trojans have been downloaded as a result of this type of attack: Mokes and Buerak. The former provides backdoor access to the victim’s device, while the latter downloads additional malware on the infected device.

Backdoors are a very dangerous type of malware. Their functionality allows threat actors to gain control over an infected machine for malicious purposes. At the same time, the user might not even suspect that the machine is being exploited.

Cybercriminals have, in the past, used updates for legitimate applications as a means of spreading malware, but the use of false security certificates is new.

“People are particularly susceptible to this type of attack because it appears on legitimate websites, ones they’ve possibly already visited. What’s more, the address listed in the iframe is, in fact, the real address of the website. The natural instinct then is to ‘install’ the recommended certificate, so they can view the content they want to. However, users should always be wary when prompted to download something by an online source – chances are, it’s not necessary,” says Victoria Vlasova, security expert at Kaspersky.

To avoid downloading potentially harmful malware on your device, Kaspersky experts recommend that you:

• Double-check the format of the URL and the spelling of the company name.

• Manually type the website address in your browser rather than visiting via a link.

• Use a security solution to protect you against a variety of cyber threats.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Kaspersky warns of active Docusign-themed phishing scams
Kaspersky Information Security
Kaspersky is warning of a rising phishing scam involving fraudulent emails pretending to be from Docusign, a globally used e-signature platform, where users are asked to enter a work login and password credentials.

Read more...
Stay safe while using AI assistants
Kaspersky Information Security News & Events AI & Data Analytics
The new DeepSeek AI assistant has attracted a lot of attention, including the interest of cybercriminals. Kaspersky experts have detected scam activity related to it.

Read more...
Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
Know who’s spying on you
Kaspersky Information Security Products & Solutions
According to the latest State of Stalkerware report, 40% of the people surveyed worldwide stated they have experienced stalking or suspect they are being spied on. A solution for Android is now available.

Read more...
Dahua launches 2-wire hybrid video intercom system
Dahua Technology South Africa Smart Home Automation Access Control & Identity Management Residential Estate (Industry)
Dahua Technology has launched a 2-Wire Hybrid Video Intercom System (the Dahua EACH Series) that redefines residential security and communication with its high image quality and easy deployment features.

Read more...
Kaspersky detects over 1 million daily tracking attempts
Kaspersky News & Events Information Security
Kaspersky's latest analysis of the 25 most prevalent web tracking services, including Google services, New Relic and Microsoft, has revealed over 38 billion instances of web trackers collecting user behaviour data in 2024, with an average of one million detections per day.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
Panasonic Industry offers multi-tier Matter Certificate Service
Smart Home Automation IoT & Automation
Panasonic Industry Europe is now offering PAN-MaX, a multi-tier Matter Certificate Service designed for device manufacturers selling in the smart home market, to simplify Matter enablement for smart home devices.

Read more...
Smart opener for gates and garages
Smart Home Automation Access Control & Identity Management
The Smart Gate and Garage Opener allows consumers to control and monitor gates and garage doors that have already been fitted with automation devices via the Yale Home app on their smartphone.

Read more...
Ring announces second generation indoor camera
Smart Home Automation Surveillance Residential Estate (Industry)
Introducing a removable manual privacy cover, Ring's latest indoor camera provides customers with increased privacy, control and peace of mind when it comes to home security.

Read more...