Cyber Security

‘FakeUpdates’ Malware Campaign – 2020 Nov 13th

By Matsco Engineering Team

‘FakeUpdates’ Malware Campaign – 2020 Nov 13th

Matsco Solutions is aware of FakeUpdates campaigns discovered by security researcher.

According to public information provided by BeepComputer, Microsoft is warning its customers about the so-called “FakeUpdates” campaigns in a non-public security advisory, attackers in the latest FakeUpdates campaign using search-engine ads to push top results for Teams software to a domain that they control and use for fake Microsoft Teams updates to deploy backdoors, which use Cobalt Strike to infect companies’ networks with malware. If victims click on the link, it downloads a payload that executes a PowerShell script, which loads malicious content.

Matsco Solutions recommends that organization take the following security measures if applicable and increase wide awareness of malware masquerading as legitimate applications such as Microsoft Teams.

  • Use web browsers that can filter and block malicious websites
  • Verify websites, sender address belong to the legitimate vendor prior to clicking any links for downloading executable content
  • Ensure Anti-Virus/Anti-Malware programs and signatures are up to date
  • Follow the principle of “Least Privilege” to limit the potential damage of infections

For further information please refer to information released by public security research community:

https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/

All resources

Get Started

Let's make technology work for you.

Get in touch about support, cloud, security, or a build-out, wherever in the world you operate.