Connect with us

Hi, what are you looking for?

Cyber Security

Hackers push fake Pokemon NFT game to take over Windows devices

Threat actors are using a well-crafted Pokemon NFT card game website to distribute the NetSupport remote access tool and take control over victims’ devices.

The website “pokemon-go[.]io,” which is still online at the time of writing, claims to be home to a new NFT card game built around the Pokemon franchise, offering users strategic fun together with NFT investment profits.

Considering the popularity of both Pokemon and NFTs, it shouldn’t be hard for the operators of the malicious portal to draw an audience to the site through malspam, social media posts, etc.

Those who click on the “Play on PC” button download an executable that looks like a legitimate game installer but, in reality, installs the NetSupport remote access tool (RAT) on the victim’s system.

The operation was uncovered by analysts at ASEC, who reports there was also a second site used in the campaign, at “beta-pokemoncards[.]io,” but it has since been taken offline.

This campaign’s first signs of activity appeared in December 2022, while earlier samples retrieved from VirusTotal showed that the same operators pushed a fake Visual Studio file instead of the Pokemon game.

Dropping the NetSupport RAT

The NetSupport RAT executable (“client32.exe”) and its dependencies are installed in a new folder in the %APPDATA% path. They are set to “hidden” to help evade detection from victims performing manual inspections on the file system.

Dropped files and contents of the configuration file
Dropped files and contents of the configuration file (ASEC)

Moreover, the installer creates an entry in the Windows Startup folder to ensure the RAT will execute upon system boot.

As NetSupport RAT (NetSupport Manager) is a legitimate program, threat actors commonly use it in the hopes it will evade security software.

NetSupport RAT interface
NetSupport RAT interface (ASEC)

The threat actors can now remotely connect to a user’s device to steal data, install other malware, or even attempt to spread further on the network.

While NetSupport Manager is a legitimate software product, it is commonly used by threat actors as part of their malicious campaigns.

In 2020, Microsoft warned about phishing actors using COVID-19-themed Excel files that dropped NetSupport RAT onto the recipients’ computers.

In August 2022, a campaign targeting WordPress sites with fake Cloudflare DDoS protection pages installed NetSupport RAT and Raccoon Stealer on victims.

NetSupport Manager supports remote screen control, screen recording, system monitoring, remote system grouping for better control, and plenty of connectivity options, including network traffic encryption.

That said, the consequences of such an infection are broad and severe, mainly concerning unauthorized access to sensitive user data and downloading further malware.

Copyright 2021 Associated Press. All rights reserved.

Source: https://www.bleepingcomputer.com/news/security/hackers-push-fake-pokemon-nft-game-to-take-over-windows-devices/

Advertisement. Scroll to continue reading.
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Cyber Security

Telegram Messenger offers global, cloud-based instant messaging with several features:- Cybersecurity researchers at Securlist recently found several Telegram mods on Google Play in various...

Cyber Security

AttackCrypt, an open-source “crypter,” was recently used by cybercriminals to hide malware binaries and avoid antivirus detection. A crypter is a kind of software that can...

Cyber Security

We are glad to present the most recent news on cybersecurity in this week’s Threat and Vulnerability Roundup from Cyber Writes.  The latest attack...

Cyber Security

The cybercrime group evaded remediation efforts by installing persistent backdoors and deploying “new and novel malware.” A Chinese-linked hacking group that security researchers say...

Copyright © 2023 Newsworthy News | Global | Political | Local | All News | Website By: Top Search SEO