Live data from Hacker News

Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

gizmodo.com.au

11–18 of 18 posts

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#11
post #7
post #6

Earlier quoted context omitted.

The article is light on the details (it's an article that digests the contents of another article - behind a paywall bypassable by having a Google referer), but it doesn't talk about how the hack works. Presumably the fake Zoom invite was a link to a non-Zoom website that promptly popped up a window to download an executable named ZoomUpgrade.exe . The victim clicked "download and run", and ta da, he installed a back…

>Alternatively the hacker could've written a browser extension, I doubt those have adequate protection... I'd bet a lot fewer people install browser extensions than install Zoom. Security isn't about absolute protection but about making things ever more difficult to exploit.

Hedge fund managers and high schoolers/teachers might have slightly different security training, but judging by the number of rubbish extensions and sites with notification permissions that I clear out of Chrome, there are definitely people out there indiscriminately installing browser extensions!

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#12
post #2

About three discussions on the front page right now are about Apple controlling the Mac platform, but this is one of the upsides. Companies that use only Macs with gatekeeper on have automatic protection against a whole class of cyber security problems.

> Companies that use only Macs with gatekeeper on have automatic protection against a whole class of cyber security problems.

So would everyone else if Apple shared their blacklists, or we had collaborative and open lists.

Using this as a reason to recommend taking the corporate OS route is deceiving, as it doesn't address the underlying roots of why antivirus is needed in the first place (systemic Capitalist exploitation, and the Elites privatizing and owning the means of production).

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#14
post #8
post #5

Earlier quoted context omitted.

It was the bullet that killed him, not the gun.

It was a fake zoom link. Zoom wasn't involved in any stage of this hack.

If that's the case, how did that link install the trojan?

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#16

> Following that, a Pakistani national Muhammad Bhatti made 64 (!) withdrawals from one bank where the money was transferred, as well as a small shopping spree, before leaving Australia. It should be easy to track the criminal.

Tracking yes, prosecuting... not so much. Pakistan does not have an active direct extradition treaty with Australia (per http://www.austlii.edu.au/au/other/dfat/treaties/notinforce/...).

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#17
post #14
post #8

Earlier quoted context omitted.

It was a fake zoom link. Zoom wasn't involved in any stage of this hack.

If that's the case, how did that link install the trojan?

It didn’t, the user did. I assume the fake link led to a page saying “you have to update your zoom” and downloaded malware. The kind of thing new macOS versions try to avoid with the new gatekeeper. Maybe the guy used windows?

Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite

#18

I have been waiting for this to happen. Any service that normalizes clicking a link in an email and encouraging the user to immediately run an autodownloaded executable is a giant security issue.

It's almost like it was designed to be malware and even couldn't be uninstalled, like malware.

Zoom is malware and I'm surprised anyone is actually using it given how politically active the company is with the ccp

Post reply on HN