meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, September 14th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 14 September 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Fake FreeDownloadManager; Foxit PDF Reader Update; macOS Metastealer; blocking NTML Hashes

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, September 14, 2023 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.3

Let's start today with a blog post by Kaspersky that hasn't really gotten a lot of attention, but I think should probably get a little bit more

0:22.1

attention, and that's a malicious free download manager for Linux that apparently has infected

0:29.6

a good number of victims and has been available for download for the last three years. This software free download manager is usually

0:41.3

distributed via a website free download manager.org and currently the website does distribute

0:49.3

what appears to be a non-backdored version. But according to Kaspersky's post, it appears that in the

0:56.6

past, sometimes when you clicked on the download button, you were redirected to the malicious

1:03.2

version of this software, which was hosted on FDMPKG.org. It is, of course, difficult to figure out that this only sometimes happens and happened

1:15.8

only in the past.

1:17.5

What helped Kaspersky here is that there are tutorial videos on YouTube that show how

1:24.0

to install this free download manager on your system,

1:28.3

and the screen recordings in these tutorial videos actually show the redirection

1:34.3

to the malicious version after first clicking on the download button

1:39.3

on the legitimate free download manager.org website.

1:44.9

The malware does include the legitimate software, but as part of the install scripts that come

1:50.4

with the Debian package.

1:53.1

There's also a DNS-based backdoor and the Bash Steeler being installed.

1:57.6

The Bash Steeler is trying to get a hold of passwords, crypto wallets and such, and then

2:04.1

exfiltrating them. All of this takes crown jobs to run and actually one thing that Kasperski

2:11.2

observed is that users then often complain about some issues that show up because of these

2:16.9

ground jobs like difficulties

2:18.8

shutting down the system. So if you're suspecting that you're affected by this particular

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.