- Cyber criminals invite victims to talk to “journalists”
- On the zoom call, they are asked to give permissions for remote access
- Those who give the permissions lose their crypto
Hackers abuse Zooms Remote Disc function to steal people’s cryptocurrency, experts have warned.
CyberSecurity scientists Trail of Bits claim to have seen the attack in nature focusing on “goals of high value”, people that the media would often contact for comments and discussion about everyday events. The attackers would reach out via social media (for example) and send them a zoom invitation via calendar and pretend to be Bloomberg journalists.
On Zoom, the striker would join with an account called “Zoom” and request remote control over the victim’s account. The victims would see a popup that says “Zoom requests remote control of your screen”, as for those used to give permissions without thinking twice, may seem like a legitimate request from a legitimate app.
Evasive comet
“What makes this attack particularly dangerous is the similarity of permission dialogue to other harmless zoom messages,” said Trail of Bits.
“Users who are used to clicking” Authorizing “on the Zoom Prompts can provide full control of their computer without realizing the consequences.”
Once the access is awarded, the attackers would move quickly, insert a stealthy back door or other means to maintain access and then disconnect from the call.
The final step is to use malware to access the victim’s cryptocurrency -draw books and sifle any means found inside.
The researchers named the group “Eviling Comet” and said the methodology is probably copied from Lazarus, the notorious North Korean state -backed unit targeting cryptic companies.
“The evasive comet -Methodology reflects the techniques behind the recent BYBIT HACK of $ 1.5 billion in February, with attackers manipulated legitimate workflows rather than exploiting coding vulnerability,” Trail of Bits said in his report.
To mitigate the risk, it would be best not to give people or apps remote access unless you are 100% sure the person is benign.
Via Bleeping computer