According to IT Home reports, the network security company Dr. Web recently published a blog post stating that it hopes that users will not download the streamlined and pirated Win10 ISO image through untrusted channels. The agency recently discovered that attackers distribute Win10 ISO images and hide mining codes in the EFI (Extensible Firmware Interface) partition, which can avoid the detection of anti-virus software. (Note: The EFI partition is a small system partition that contains the bootloader and related files that execute before the operating system starts.)
These malicious Win10 ISO images contain malicious applications. Once the device is infected, it will monitor the process explorer, task manager, process monitor, process, etc. Once the cryptocurrency wallet address in the clipboard is found, it will be immediately replaced by the attacker default address. Dr. Web said it investigated the redirected encrypted wallet address and found at least $19,000 worth of cryptocurrency on the wallet account. #新闻frontier# #Content Star#
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
According to IT Home reports, the network security company Dr. Web recently published a blog post stating that it hopes that users will not download the streamlined and pirated Win10 ISO image through untrusted channels. The agency recently discovered that attackers distribute Win10 ISO images and hide mining codes in the EFI (Extensible Firmware Interface) partition, which can avoid the detection of anti-virus software. (Note: The EFI partition is a small system partition that contains the bootloader and related files that execute before the operating system starts.)
These malicious Win10 ISO images contain malicious applications. Once the device is infected, it will monitor the process explorer, task manager, process monitor, process, etc. Once the cryptocurrency wallet address in the clipboard is found, it will be immediately replaced by the attacker default address. Dr. Web said it investigated the redirected encrypted wallet address and found at least $19,000 worth of cryptocurrency on the wallet account. #新闻frontier# #Content Star#