Skip to main content

Security experts warn of new hacker strategy targeting Windows drivers

As if there weren’t enough threats to your Windows computer already, here is another one to be careful with. Kaspersky reports that tens of thousands of compromised PCs are infected as cybercriminals advertise fake activators and cracks to lure in unsuspecting users for distinct software such as AutoCAD, JetBrains, and Foxit PDF Editor.

The malicious package named SteelFox has been quietly spreading since February 2023, but its distribution has exploded recently. The malware is dispersed using torrent trackers and forums, where it is used as a tool to activate authentic versions of the previously mentioned software.

Recommended Videos

The experts at Kaspersky warn that the malware mimics cryptocurrencies and steals sensitive financial and non-financial information from your devices. When you install the fake crack, a vulnerable driver called WinRingO.sys is added that restores CVE-2021-41285 and CVE-2020-14979, four- and three-year-old vulnerabilities that give hackers full access to your PC.

When hackers access these vulnerabilities, they insert XMRig, a program that steals computer resources to mine cryptocurrency, an attack known as cryptojacking. XMRig uses your electricity, PC power, and the internet to mine Monero and other cryptocurrencies, making your PC useless. An info stealer is also inserted to retrieve data from 13 web browsers, including browsing history, credit card info, session cookies, network data, and system information. A Remote Desktop Protocol (RDP) connection is also established.

The report also mentioned a malicious post that included complete instructions on how to launch the software illegally. Further, Kaspersky says that “the execution chain looks legitimate until the moment the files are unpacked.” The damaging software is inserted in the process and adds the machine code that launches Steelfox.

Kaspersky also says it has blocked 11,000 attacks thus far, but the number can easily be much higher. Affected users are worldwide, including in countries such as Mexico, Brazil, Russia, China, UAE, Algeria, Egypt, Vietnam, Sri Lanka, and India.

You can stay safe by only downloading software from legitimate sources, and having top-tier antivirus software such as Bitdefender is a great idea.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Bing Chat just beat a security check to stop hackers and spammers
A depiction of a hacker breaking into a system via the use of code.

Bing Chat is no stranger to controversy -- in fact, sometimes it feels like there’s a never-ending stream of scandals surrounding it and tools like ChatGPT -- and now the artificial intelligence (AI) chatbot has found itself in hot water over its ability to defeat a common cybersecurity measure.

According to Denis Shiryaev, the CEO of AI startup Neural.love, chatbots like Bing Chat and ChatGPT can potentially be used to bypass a CAPTCHA code if you just ask them the right set of questions. If this turns out to be a widespread issue, it could have worrying implications for everyone’s online security.

Read more
Hackers have a new way of forcing ransomware payments
kaspersky releases tool to counteract cryptxxx ransomware

Bad actors are becoming craftier with their methods of ransomware attacks by targeting backup storage to force organizations to pay a ransom, according to the software company Veeam.

In the event of a ransomware attack, companies typically have two options: pay the ransom and hope that their data can be restored through a decryptor sent by the bad actors or ignore the ransom demands and restore their data via a backup option, TechRadar reports.

Read more
Chinese hackers targeting critical U.S. infrastructure, Microsoft warns
chinese hackers caught targeting vital us infrastructure china flags

State-sponsored hackers based in China have been working to compromise critical infrastructure in the U.S., Microsoft said on Wednesday. It’s thought the attacks could lead to the disruption of important communications between the U.S. and its interests in Asia during future crises.

Notable target sites include Guam, a small island in the Pacific with an important U.S. army base that could play an important role in any clash with China over Taiwan.

Read more