That PowerShell ‘fix’ for your root cert ‘problem’ is a malware loader in disguise

Crafty criminals are targeting thousands of orgs around the world in social-engineering attacks that use phony error messages to trick users into running malicious PowerShell scripts.  This latest Windows malware distribution campaign uses fake Google Chrome, Microsoft Word, and OneDrive error messages that look kinda like real warnings. After visiting a legit but compromised website, victims see some kind of pop-up text box in their browser telling them something went wrong – it’s an old but highly effective trick.

Source: The Register

 


Date:

Categorie(s):