It looks like you're using an Ad Blocker.

Please white-list or disable AboveTopSecret.com in your ad-blocking tool.

Thank you.

 

Some features of ATS will be disabled while you continue to use an ad-blocker.

 

Oh no, that James Webb Space Telescope snap might actually contain malware

page: 1
9

log in

join
share:

posted on Sep, 1 2022 @ 04:29 AM
link   
Morning ATS Colleagues.

I popped this into Space Exploration as browsers here are likely more inclined to be looking at this image.

theregister.com_webb_telescope_malware

SNIP-
Scumbags are using a photo from the James Webb Space Telescope to smuggle Windows malware onto victims' computers – albeit in a roundabout way.

The malicious code, written in Go, is hidden in a .jpeg of the stunning first proper image taken by the recently deployed spacecraft.

More specifically, the obfuscated code is Base64-encoded and included in the .jpeg disguised as a certificate. The payload, dubbed GO#WEBBFUSCATOR, was not detected as malicious by antivirus engines in VirusTotal. This is all according to researchers at cybersecurity firm Securonix, who said they spotted and inspected the .jpeg's contents.

Just so people are aware eh.

Cheers and beers people.



posted on Sep, 1 2022 @ 05:08 AM
link   
a reply to: Cymru

Thanks for the info...

Very clever and devious.




posted on Sep, 1 2022 @ 05:32 AM
link   
a reply to: Cymru

Who? Who are the scumbags?



posted on Sep, 1 2022 @ 05:33 AM
link   
a reply to: Cymru

Good find Cymru.


I seem to recall picking up some ransomware, right good few years back now, down to what i think was an infected jpeg.

Easy enough to reinstall the OS, but because i was silly enough to have my backup drive plugged in at the time, i lost all the family photos and video to the tune of about 5 years worth.



posted on Sep, 1 2022 @ 05:52 AM
link   
a reply to: Cymru

How low certain groups can stoop is beyond me.



posted on Sep, 1 2022 @ 07:35 AM
link   
a reply to: Cymru

I wondered how that Geico ad got on the arm of a spiral Galaxy...



posted on Sep, 1 2022 @ 09:06 AM
link   
Not always mind you, but sometimes I'm glad I use an 8-year-old Mac.



posted on Sep, 1 2022 @ 09:47 AM
link   
a reply to: andy06shake

I have a 2TB drive from a failed NAS to recover.

In no rush to see ex Mrs' pics so it can stay in the attic for now



posted on Sep, 1 2022 @ 10:26 AM
link   
a reply to: Cymru


The infection starts with a phishing email that contains a Microsoft Office attachment named Geos-Rates[.]docx that, when opened, downloads a malicious template file that contains an obfuscated VBA macro that automatically executes – if the macro is allowed to run.

And people still get caught by phishing/malicious emails with dodgy attachments...



posted on Sep, 1 2022 @ 10:38 AM
link   

originally posted by: wildespace
a reply to: Cymru


The infection starts with a phishing email that contains a Microsoft Office attachment named Geos-Rates[.]docx that, when opened, downloads a malicious template file that contains an obfuscated VBA macro that automatically executes – if the macro is allowed to run.

And people still get caught by phishing/malicious emails with dodgy attachments...


Didn't Micro$ recently re-enable macros as well ?

I got that backwards


www.bleepingcomputer.com...



posted on Sep, 1 2022 @ 12:54 PM
link   
a reply to: Bluntone22

Customise and save with Liberty Mutual. I customise everything, like Marco's backpack.
*drone*



new topics

top topics



 
9

log in

join