meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 17th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 17 April 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Fake Chrome Errors; Chromium 0-Day; LAPS Compatibility Issues; Manage Engine

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 17, 2023 edition of the Sansonet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Augusta, Georgia.

0:14.2

On Friday, NTT security, a Japanese security company posted an interesting blog post

0:19.9

describing a group of attacks that

0:23.5

uses fake Chrome error messages. Now, just about a week ago, we noted that the attack against

0:31.5

eFile.com used a similar technique. However, these two attacks appear to be not related, at least after

0:40.5

the error message, we do see quite different behavior.

0:44.9

The attack entity describes appears to be a step more sophisticated.

0:50.5

It does do privilege escalation.

0:53.9

Apparently, one way it's doing that is by using vulnerable drivers,

0:59.0

but it then also not only installs a crypto coin miner, but it also does use additional techniques to, for example,

1:09.0

exempt that crypto coin miner from Microsoft Defenders scans.

1:14.6

It'll also schedule itself and then terminate Windows updates.

1:20.5

So overall, in particular, the privilege escalation part is quite a bit more sophisticated

1:24.9

than the more clumsy malware that we have seen from the eFile.com attacker.

1:31.0

So these fake error measures, certainly something

1:33.8

that you should include in your security awareness presentations.

1:37.8

They do trick the user into installing the malicious update.

1:41.8

And that's probably the message to get across here

1:43.8

that these error messages,

1:45.7

while they look okay,

1:48.0

they look like something legitimate,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.