Thursday, February 2, 2023
Learning Code
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
Learning Code
No Result
View All Result
Home JavaScript

Trojanized Comm100 Live Chat app installer distributed a JavaScript backdoorSecurity Affairs

learningcode_x1mckf by learningcode_x1mckf
October 3, 2022
in JavaScript
0
Trojanized Comm100 Live Chat app installer distributed a JavaScript backdoorSecurity Affairs
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


A menace actor used a trojanized installer for the Comm100 Reside Chat utility to distribute a JavaScript backdoor.

Cybersecurity agency CrowdStrike disclosed particulars of a provide chain assault that concerned using a trojanized installer for the Comm100 Reside Chat utility to distribute a JavaScript backdoor.

Comm100 is a supplier of customer support and communication merchandise that serves over 200,000 companies. On the time of this writing it’s unclear what number of prospects of the corporate had been impacted by the assault.

The assault came about from a minimum of September 27, 2022 by the morning of September 29, 2022. The malicious installer was used to contaminate organizations in a number of sectors, together with the economic, healthcare, expertise, manufacturing, insurance coverage and telecommunications sectors in North America and Europe.

CrowdStrike researchers assess with average confidence that the menace actor behind this provide chain assault probably has a China nexus.

The malicious code was delivered by way of a signed Comm100 installer that was downloadable from the corporate’s web site

Comm100

“Malware is delivered by way of a signed Comm100 installer that was downloadable from the corporate’s web site. The installer was signed on September 26, 2022 at 14:54:00 UTC utilizing a sound Comm100 Community Company certificates.” reads a report printed by CrowdStrike. “CrowdStrike Intelligence can affirm that the Microsoft Home windows 7+ desktop agent hosted at https[:]//dash11.comm100[.]io/livechat/electron/10000/Comm100LiveChat-Setup-win.exe that was accessible till the morning of September 29 was a trojanized installer.”

Comm100 addressed the difficulty by releasing a clear, up to date installer, version 10.0.9.  

The weaponized executable was noticed containing is a JavaScript used to execute a second-stage JavaScript code hosted on a distant server. This second-state Javascript set up a distant shell on the contaminated system. Attackers additionally deployed a malicious loader DLL named MidlrtMd.dll that launches an in-memory shellcode to inject an embedded payload into a brand new occasion of notepad.exe.

“The injected payload connects to the malicious C2 area api.microsoftfileapis[.]com, which resolved to the IP deal with 8.219.167[.]156 on the time of the incident.” continues the report.

The attackers used the Microsoft Metadata Merge Utility binary to load a the MidlrtMd DLL.

“Moreover, CrowdStrike Intelligence assesses with average confidence that this actor probably has a China nexus. This evaluation relies on the presence of Chinese language-language feedback within the malware, aforementioned ways, methods and procedures (TTPs), and the connection to the concentrating on of on-line playing entities in East and Southeast Asia — a beforehand established space of focus for China-nexus focused intrusion actors. CrowdStrike Intelligence prospects have entry to extra reporting associated to this actor.”

The report contains Indicators of Compromise (IoCs) for this assault.

Observe me on Twitter: @securityaffairs and Facebook

Pierluigi Paganini

(SecurityAffairs – hacking, Comm100)











Share On






Source link

You might also like

Pay What You Want for this Learn to Code JavaScript Certification Bundle

How to have a Smooth/Fast scroll in mobile popup window? – JavaScript – SitePoint Forums

JavaScript Token (JS) Do the Risks Outweigh the Rewards Wednesday?

Share30Tweet19
learningcode_x1mckf

learningcode_x1mckf

Recommended For You

Pay What You Want for this Learn to Code JavaScript Certification Bundle

by learningcode_x1mckf
February 2, 2023
0
Pay What You Want for this Learn to Code JavaScript Certification Bundle

Deal Neowin Offers · Oct 4, 2021 - Up to date Jan 31, 2023 13:00 EST Jumpstart your profitable profession in coding and programmingRight now's highlighted deal comes...

Read more

How to have a Smooth/Fast scroll in mobile popup window? – JavaScript – SitePoint Forums

by learningcode_x1mckf
February 2, 2023
0
Different server for Google API – JavaScript – SitePoint Forums

Hello Associates,Sorry I need to appropriate the positioning tackle to this: http://dev.harfrooz.com/I searched quite a bit and I came upon that my downside is expounded to iscroll.js File....

Read more

JavaScript Token (JS) Do the Risks Outweigh the Rewards Wednesday?

by learningcode_x1mckf
February 1, 2023
0
JavaScript Token (JS) Do the Risks Outweigh the Rewards Wednesday?

News Home Wednesday, February 01, 2023 07:38 AM | InvestorsObserver Analysts JavaScript Token receives a excessive risk score from InvestorsObserver evaluation. The proprietary scoring system analyzes how a...

Read more

Discord Rich Presence – JavaScript – SitePoint Forums

by learningcode_x1mckf
February 1, 2023
0
Different server for Google API – JavaScript – SitePoint Forums

Hiya! Extraordinarily new to java-script and I’m making an attempt to make use of discordjs-rpc to make one thing that can change my standing based mostly on no...

Read more

WebAssembly vs. JavaScript: Security, Speed, Flexibility

by learningcode_x1mckf
February 1, 2023
0
WebAssembly vs. JavaScript: Security, Speed, Flexibility

In direction of the start of what's popularly referred to as the World Extensive Net, there was JavaScript. JavaScript has been round since 1995 when Brendan Eich created...

Read more
Next Post
Review: Visual Studio Code shines for Java

Review: Visual Studio Code shines for Java

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

JavaScript Hydration Is a Workaround, Not a Solution

JavaScript Hydration Is a Workaround, Not a Solution

September 25, 2022
10 Best Software Engineering Practices for Java | by DN Tech | Nov, 2022

10 Best Software Engineering Practices for Java | by DN Tech | Nov, 2022

November 5, 2022
Build a Tic-Tac-Toe Game Engine With an AI Player in Python – Real Python

Build a Tic-Tac-Toe Game Engine With an AI Player in Python – Real Python

October 19, 2022

Browse by Category

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

RECENT POSTS

  • Java :Full Stack Developer – Western Cape saon_careerjunctionza_state
  • Pay What You Want for this Learn to Code JavaScript Certification Bundle
  • UPB Java Jam brings coffeehouse vibes to Taylor Down Under | Culture

CATEGORIES

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

© 2022 Copyright Learning Code

No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#

© 2022 Copyright Learning Code

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?