Earlier quoted context omitted.
The article is light on the details (it's an article that digests the contents of another article - behind a paywall bypassable by having a Google referer), but it doesn't talk about how the hack works. Presumably the fake Zoom invite was a link to a non-Zoom website that promptly popped up a window to download an executable named ZoomUpgrade.exe . The victim clicked "download and run", and ta da, he installed a back…
>Alternatively the hacker could've written a browser extension, I doubt those have adequate protection... I'd bet a lot fewer people install browser extensions than install Zoom. Security isn't about absolute protection but about making things ever more difficult to exploit.
Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
11–18 of 18 posts
Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#12About three discussions on the front page right now are about Apple controlling the Mac platform, but this is one of the upsides. Companies that use only Macs with gatekeeper on have automatic protection against a whole class of cyber security problems.
So would everyone else if Apple shared their blacklists, or we had collaborative and open lists.
Using this as a reason to recommend taking the corporate OS route is deceiving, as it doesn't address the underlying roots of why antivirus is needed in the first place (systemic Capitalist exploitation, and the Elites privatizing and owning the means of production).
Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#13It should be easy to track the criminal.
Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#14Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#15Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#16> Following that, a Pakistani national Muhammad Bhatti made 64 (!) withdrawals from one bank where the money was transferred, as well as a small shopping spree, before leaving Australia. It should be easy to track the criminal.
Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#17Earlier quoted context omitted.
It was a fake zoom link. Zoom wasn't involved in any stage of this hack.
If that's the case, how did that link install the trojan?
Re: Hacker Nearly Stole $8M from Aussie Hedge Fund Using a Fake Zoom Invite
#18I have been waiting for this to happen. Any service that normalizes clicking a link in an email and encouraging the user to immediately run an autodownloaded executable is a giant security issue.
Zoom is malware and I'm surprised anyone is actually using it given how politically active the company is with the ccp