• Home
  • About
  • Contact us
Tech News, Magazine & Review WordPress Theme 2017
  • Computing
  • Entertainment
  • Gaming
  • Mobile
  • Science
  • Security
  • Services
  • Software
  • Space
No Result
View All Result
  • Computing
  • Entertainment
  • Gaming
  • Mobile
  • Science
  • Security
  • Services
  • Software
  • Space
Technovanguard — Be at the forefront of technology news
No Result
View All Result

Symantec says that hackers distributed a modified version of VLC and exploited it for malware attacks

Justin Rowell by Justin Rowell
29.09.2022
Home Software

Last week, news began circling around that VLC was being abused by hackers to inject some malware. The issue came to light after Symantec published a report on its Security Threat Intelligence blog.

Hackers distributed a modified version VLC to launch a malware attack

The Broadcom-owned company, which makes Norton Antivirus, revealed that a group of hackers, which it claims are affiliated to the Chinese government, were conducting cyber-espionage campaigns targeting organizations across the world.

Symantec says that the campaign primarily targeted victims in government-related institutions or NGOs in education and religion, telecom, legal and pharmaceutical sectors. The malware attack campaign, called Cicada or APT10, was first tracked last year. It was active in February 2022, and could still be ongoing. Attackers are targeting victims via Microsoft Exchange Servers in unpatched system deployments, to gain access to their machines. The hackers use various tools in addition to a custom loader, and a backdoor called Sodamaster.

Hackers distributed a modified version of VLC to use it for triggering a custom malware loader

One of these tools is a modified version of the popular open source media player, VLC. Symantec’s Security Threat Intelligence blog mentions the following statement.

“The attackers also exploit the legitimate VLC Media Player by launching a custom loader via the VLC Exports function, and use the WinVNC tool for remote control of victim machines.”

This statement’s wording is quite confusing, and was misinterpreted by some blogs, who wrote that VLC is vulnerable and that hackers are using it to launch malware attacks. This is not correct, VLC is not the reason for the malware attacks like these websites allege. The rest of the report should be taken into context.

The second section of the report (highlighted in the image) mentions that attackers needed access to the victim machines, before they could launch the malware attack.  This was confirmed by a member of Symantec’s Threat Hunter Team, in a statement released to Bleeping Computer. They said that some hackers took the clean version of VLC, added a malicious DLL file to it and distributed it, aka DLL side-loading. This file is located in the same folder as the export function’s path, and is used by the attackers to launch a custom malware loader.

So it is evident there are at least two different requirements for this attack to happen: a compromised system, and a modified version of VLC (among the other tools that were used).

Is VLC safe to use?

Yes, it is. As long as you download VLC from the official website (or a trustworthy site), your computer should be safe from malware, because it does not contain the malicious DLL File used in these attacks.

When you download a program from a third-party site, and that website had stealthily embedded some files into the package, it is no longer an official release from the developer. It becomes a modified version that could potentially be malicious. When such files get circulated, people who use them are at the risk of attacks. Hackers use various tricks such as malvertising, e.g. use a popular program’s icon to convince people into thinking they are downloading the original file, while in fact they are downloading a malware that could infect their system, and could even spread to other users.

If you are worried whether a program that you have could have been tampered with, you may want to upload the installer to an online service like VirusTotal, to confirm that it is safe to use. Another option is to verify whether the hash values to see if the checksum matches that of the official release. e.g. VLC lists its hash values on its archive site. Keep your operating system and antivirus software up-to-date, and use an ad blocker like uBlock Origin to minimize the chances of malware attacks.

Thank you for being a Ghacks reader. The post Symantec says that hackers distributed a modified version of VLC and exploited it for malware attacks appeared first on gHacks Technology News.


Next Post
Hydrogel boosts ‘attack power’ of cells that fight cancer

Hydrogel boosts ‘attack power’ of cells that fight cancer

Recommended.

How to Preserve Your Capital in a Tightened Regulatory Environment

How to Preserve Your Capital in a Tightened Regulatory Environment

01.02.2024
Tech Industry Faces Unprecedented Workforce Challenges as Layoffs Surpass 2022 Numbers

Tech Industry Faces Unprecedented Workforce Challenges as Layoffs Surpass 2022 Numbers

01.02.2024

Trending.

Google’s Financial Triumphs and Challenges: 100 Million Google One Subscribers, Cloud Profits, and Strategic Moves

Google’s Financial Triumphs and Challenges: 100 Million Google One Subscribers, Cloud Profits, and Strategic Moves

01.02.2024
Singtel Collaborates with Nvidia, Unveils Nxera for AI-Focused Datacenters Across Southeast Asia

Singtel Collaborates with Nvidia, Unveils Nxera for AI-Focused Datacenters Across Southeast Asia

01.02.2024
Technovanguard — Be at the forefront of technology news

Technovanguard - The latest news from the world of IT and modern technologies.

Categories

  • Computing
  • Entertainment
  • Gaming
  • Internet
  • Mobile
  • News
  • Science
  • Security
  • Services
  • Software
  • Space
  • Без рубрики

Tags

best bitcoin casino best bitcoin gambling site best crypto casino bitcoin gambling site btc casino cloud services digital services FEATUREDNEWS IT linkedin connection message linkedin connection request template linkedin connect message examples linkedin networking message template linkedin sales message Recommended top bitcoin casinos Trending

Recent News

Lessons From The Trading Floor: Building Trust In The CFD Market

21.05.2025
Residential homes made of foam

Prejudice to Foam and Its Impact on People’s Lives

02.04.2025
  • Home
  • About
  • Contact us

© 2021 technovanguard.com. Submit news release

No Result
View All Result
  • Computing
  • Entertainment
  • Gaming
  • Mobile
  • Science
  • Security
  • Services
  • Software
  • Space

© 2021 technovanguard.com. Submit news release