HackRead reports that U.S. government agencies and European critical infrastructure entities accounted for most of the 469 devices infected with a more clandestine version of the CastleLoader malware loader.Intrusions involved the exploitation of the ClickFix social engineering technique in fraudulent update or verification pop-ups to lure targets into executing CastleLoader, which usually takes the guise of an Inno Setup-using package and runs an AutoIT script for subsequent compromise, according to ANY.RUN researchers. CastleLoader then proceeds to hijack the Windows tool "jsc.exe" with malicious code before communicating with its command-and-control server for the retrieval of information-stealing payloads and remote access trojans.With the memory-based concealment of CastleLoader making the malware undetectable by traditional antivirus systems, organizations have been urged by security experts to not only bolster defenses against technical backdoors but also increase vigilance on spurious pop-up alerts that could facilitate malware injections.
Malware, Critical Infrastructure Security
Novel CastleLoader variant facilitates extensive critical infrastructure compromise
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
