Attackers have used a malicious Google ad with Homebrew's proper "brew.sh" URL to redirect to the typosquatted "brewe[.]sh" site, which lures targets into downloading the package manager that enables infostealer malware execution, according to security researcher Ryan Chenkie.
Threat actors leveraged a phishing webpage luring targets into downloading a legitimate software-spoofing Microsoft Installer package that conceals its malicious nature by launching the app while executing a malicious DLL to deploy the multi-stage PNGPlug loader, a report from Intezer showed.
STAC5143 commenced its attacks with the delivery of a deluge of spam messages followed by a Teams call purporting to be from "Help Desk Manager" that sought Teams-based remote screen control access to enable command execution and backdoor deployment, according to an analysis from Sophos.
Aside from engaging in a fraud scheme against the Texas Department of Motor Vehicles via smishing victim data, Honesty and his co-conspirators also dabbled in bogus Paycheck Protection Program loan applications and fake tax returns from April to October 2021 that led the Small Business Administration to lose more than $500,000, court documents showed.
Installation of Tanzeem or Tanzeem Update triggers a bogus chat page containing a "Start Chat" button, which when clicked would lure targets into permitting accessibility permissions as the app seeks permissions enabling contact, call log, location, account information, and external storage file exfiltration activities, according to an analysis from Cyfirma.