Tricky Chinese-Targeted Trojan Bypasses Authentication
released on 2019-08-12 @ 04:40:13 PM
FortiGuard Labs uncovered a new campaign targeted at Chinese-speakers using malware that bypasses normal authentication by exploiting known WinRAR file (cve-2018-20250) and RTF file (cve-2017-11882) vulnerabilities. This attack uses a watering hole attack strategy to target Chinese-speaking users by delivering malware through a hacked Chinese news site. Based on their analysis, the campaign also appears to be experimental because it uses so many different techniques and tools to target this end user community.