{"id":2950,"date":"2021-06-03T20:51:30","date_gmt":"2021-06-04T01:51:30","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2950"},"modified":"2021-06-03T20:51:31","modified_gmt":"2021-06-04T01:51:31","slug":"poisoned-installers-what-is-this-threat","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/","title":{"rendered":"Poisoned Installers &#8211; What is this threat?"},"content":{"rendered":"\n<p>Ongoing multi-vendor investigations into the SolarWinds megahack took another turn this week with the discovery of new malware artifacts that could be used in future supply chain attacks. According to a new report, the latest wave of attacks attributed to the Nobelium threat actor includes a custom downloader that is part of a &#8220;poisoned update installers&#8221; for electronic keys used by the Ukrainian government. <\/p>\n\n\n\n<p>Sentinel, one of the leading threat researchers, Juan Andr\u00e9s Guerrero-Saade, documented the latest finding in a blog post that advances previous Microsoft and Volexity investigations. &#8220;At this time, the means of distribution of the poisoned update installers are unknown. It is possible that these update files are being used as part of a specific regional supply chain attack.<\/p>\n\n\n\n<p>In particular, one of these NativeZone downloaders is being used as part of a nifty poisoned installer targeting Ukrainian government security applications. A zip file is used to package legitimate components together with a malicious DLL, the malicious KM.Filesystem.dll was designed to impersonate a legitimate component of the cryptographic keys of the Ukraine Institute of Technology of the same name. It even mimics the same two exported functions as the original.<\/p>\n\n\n\n<p>We do not refer to this as a supply chain attack, as we lack visibility into their means of distribution. The poisoned installer can be delivered directly to the relevant victims who depend on this regional solution. Alternatively, the attackers may have found a way to abuse an internal resource to distribute their malicious update.<\/p>\n\n\n\n<p><strong><em>Check also:<\/em><\/strong><br><a href=\"https:\/\/truxgoservers.com\/blog\/snip3-tool-that-enchances-the-dangerous-rat-threat\/\">Snip3 tool that enchances the dangerous RAT threat<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\">Vovalex \u2013 Ransomware posing as Windows utilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ongoing multi-vendor investigations into the SolarWinds megahack took another turn this week with the discovery of new malware artifacts that could be used in future supply chain attacks. According to a new report, the latest wave of attacks attributed to the Nobelium threat actor includes a custom downloader that is part of a &#8220;poisoned update [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2951,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2950","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Poisoned Installers - What is this threat? - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Poisoned Installers - What is this threat? - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-04T01:51:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-04T01:51:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"996\" \/>\n\t<meta property=\"og:image:height\" content=\"596\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Poisoned Installers &#8211; What is this threat?\",\"datePublished\":\"2021-06-04T01:51:30+00:00\",\"dateModified\":\"2021-06-04T01:51:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/\"},\"wordCount\":274,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Poison.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/\",\"name\":\"Poisoned Installers - What is this threat? - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Poison.jpg\",\"datePublished\":\"2021-06-04T01:51:30+00:00\",\"dateModified\":\"2021-06-04T01:51:31+00:00\",\"description\":\"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Poison.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Poison.jpg\",\"width\":996,\"height\":596},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/poisoned-installers-what-is-this-threat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Poisoned Installers &#8211; What is this threat?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Poisoned Installers - What is this threat? - Truxgo Server Blog","description":"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/","og_locale":"es_MX","og_type":"article","og_title":"Poisoned Installers - What is this threat? - Truxgo Server Blog","og_description":"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers","og_url":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-04T01:51:30+00:00","article_modified_time":"2021-06-04T01:51:31+00:00","og_image":[{"width":996,"height":596,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Poisoned Installers &#8211; What is this threat?","datePublished":"2021-06-04T01:51:30+00:00","dateModified":"2021-06-04T01:51:31+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/"},"wordCount":274,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/","url":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/","name":"Poisoned Installers - What is this threat? - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg","datePublished":"2021-06-04T01:51:30+00:00","dateModified":"2021-06-04T01:51:31+00:00","description":"As we well know, Nobelium did their thing again, now it has been discovered that these cybercriminals used a threat called Poisoned Installers","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Poison.jpg","width":996,"height":596},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/poisoned-installers-what-is-this-threat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Poisoned Installers &#8211; What is this threat?"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2950"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2950\/revisions"}],"predecessor-version":[{"id":2966,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2950\/revisions\/2966"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2951"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}