Just in:
Qualcomm secures access to Huawei LogicFolding patents // DITP Promotes Thailand’s Entertainment Industry on the Global Stage with “Thai Night Busan 2026” at ACFM in the Republic of Korea // Rasmal, Bilişim Vadisi forge Gulf-Türkiye startup link // Saudi sets six-year-low Arab Light discount in Asia // Brother “Managed Print Service” Enables Businesses to Reduce Operating Costs and Enhance Efficiency with Flexible Deployment // NOAA projects very strong El Niño through winter // Israel’s top court restores Arab parties to ballot // Netanyahu links Flydubai attack to election security warnings // Katherine Ryan returns to Dubai Comedy Festival // Qupital Unveils World’s First AI-Driven On-Chain E-Commerce Lending Protocol, Accelerating Web3 Global Trade Finance // CEC’s Unlawful Decisions Will Be Annulled Observed Supreme Court // US court terminates LIBRA and M3M3 investor case // Trump rebrand propels Slovenia’s .si domain registrations // Investigators uncover 9/11-style plan behind flydubai attack // Supreme Court weighs limits on corporate climate lawsuits // Etihad Rail connectivity may reshape UAE property demand // NAMAA Revolutionizes Food Delivery in the Middle East with the Launch of Future Foods and Picnic // DeepSeek broadens Huawei software challenge to Nvidia // Thailand’s LTR Visa Hits 12,000 Approvals in Four Years, Adding USD 1.28 Billion to the Economy // Dr Maye Musk, author, supermodel, and dietitian, speaks at the Prudential Leadership Forum //

Microsoft’s Windows warning: Hackers hijacked software updater with in-memory malware

windows 10 hero gif

5b-windows-defender-atp-detecting-anomalous-updater-behavior.png

Microsoft has shown how Windows Defender ATP detected anomalous updater behavior.


Image: Microsoft

Microsoft is warning software vendors to protect their updater processes after discovering a “well-planned, finely orchestrated” attack that hijacked an unnamed editing tool’s software supply chain.

As Microsoft’s threat response group explains, the attackers used the update mechanism of a popular but unnamed piece of editing software to gain a foothold in several high-profile technology and financial organizations. The software vendor itself was also under attack, it says.

The espionage campaign, dubbed WilySupply by Microsoft, is likely to be financially motivated and target updaters to reach mostly finance and payment-industry firms.

In this case, they used the updater to deliver an “unsigned, low-prevalence executable” before scanning the victim’s network and establishing remote access.

Attacking the update process of trusted software is a nifty side door for attackers, since users rely on the mechanism to receive valid updates and patches.

Microsoft notes the same technique has been used in a number of attacks, such as a 2013 breach of several South Korean organizations via a malicious version of an installer from storage service SimDisk.

Attackers have the added benefit of access to free open-source pen-testing tools like Evil Grade, which helps exploit faulty update implementations to inject bogus software updates. As Microsoft notes, WilySupply did just this, shielding the attackers from attribution through unique tactics and tools.

The other pen-testing tool the attackers used was Meterpreter, the in-memory component of the Metaplsoit framework.

“The downloaded executable turned out to be a malicious binary that launched PowerShell scripts bundled with the Meterpreter reverse shell, which granted the remote attacker silent control. The binary is detected by Microsoft as Rivit,” Microsoft notes.

Despite the reliance on commodity tools, Microsoft notes a few traits typical of advanced attackers, including the use of self-destructing initial binary, and a memory-only or fileless payload to evade antivirus detection.

Security firm Kaspersky in February reported a rise of in-memory malware attacks on banks across the globe, with attackers using Meterpreter and standard Windows utilities to carry out the attacks. As the company noted, the URL responsible for downloading Meterpreter was “adobeupdates.sytes[.]net”.

Microsoft traced the source of infections at customer sites to the compromised updater with Windows Defender Advanced Threat Protection (ATP) console, its Windows 10 security feature for containing and investigating malware outbreaks.

“By utilizing the timeline and process-tree views in the Windows Defender ATP console, we were able to identify the process responsible for the malicious activities and pinpoint exactly when they occurred. We traced these activities to an updater for the editing tool,” says Microsoft.

“Forensic examination of the Temp folder on the affected machine pointed us to a legitimate third-party updater running as service. The updater downloaded an unsigned, low-prevalence executable right before malicious activity was observed.”

Read more on Windows security

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Hong Kong Residential Market Sentiment Turns Cautious as Interest Rate Outlook Shifts // Israel’s top court restores Arab parties to ballot // Corporate Sector Is Growing Well Despite Iran War, Poor Monsoon // Investigators uncover 9/11-style plan behind flydubai attack // Rasmal, Bilişim Vadisi forge Gulf-Türkiye startup link // Supreme Court weighs limits on corporate climate lawsuits // Trump rebrand propels Slovenia’s .si domain registrations // Dr Maye Musk, author, supermodel, and dietitian, speaks at the Prudential Leadership Forum // Vingroup And Alstom Sign Technology License Agreement To Develop Hanoi’s Next-Generation Urban Rail Network // Ethiopian troops reclaim Mekelle airport as Tigray leaders retreat // DITP Promotes Thailand’s Entertainment Industry on the Global Stage with “Thai Night Busan 2026” at ACFM in the Republic of Korea // US court terminates LIBRA and M3M3 investor case // Middle East crude exports regain pre-war pace // Katherine Ryan returns to Dubai Comedy Festival // NAMAA Revolutionizes Food Delivery in the Middle East with the Launch of Future Foods and Picnic // Saudi sets six-year-low Arab Light discount in Asia // Etihad Rail connectivity may reshape UAE property demand // HID Enhances FARGO® DTC Printer Line to Help Organizations Issue Faster, More Secure ID Cards // Brother “Managed Print Service” Enables Businesses to Reduce Operating Costs and Enhance Efficiency with Flexible Deployment // Yemen government begins nationwide offensive against Houthis //