• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ukrainian hacker suspected to be behind "free download manager" malware

Ukrainian Hacker Suspected to be Behind “Free Download Manager” Malware Attack

You are here: Home / General Cyber Security News / Ukrainian Hacker Suspected to be Behind “Free Download Manager” Malware Attack
September 21, 2023

The maintainers of No cost Obtain Supervisor (FDM) have acknowledged a security incident relationship again to 2020 that led to its web-site getting made use of to distribute destructive Linux software program.

“It appears that a particular web web site on our site was compromised by a Ukrainian hacker group, exploiting it to distribute malicious software,” it stated in an warn past week. “Only a modest subset of users, specially all those who tried to obtain FDM for Linux in between 2020 and 2022, ended up most likely exposed.”

Considerably less than .1% of its visitors are believed to have encountered the issue, introducing it may well have been why the issue went undetected until finally now.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The disclosure arrives as Kaspersky disclosed that the project’s site was infiltrated at some stage in 2020 to redirect pick Linux customers who tried to obtain the software program to a destructive website hosting a Debian deal.

The offer was even more configured to deploy a DNS-based mostly backdoor and in the long run serve a Bash stealer malware capable of harvesting sensitive facts from compromised techniques.

FDM claimed its investigation uncovered a vulnerability in a script on its web-site that the hackers exploited to tamper with the obtain website page and direct the internet site website visitors to the faux area deb.fdmpkg[.]org hosting the destructive .deb file.

“It had an «exception list» of IP addresses from different subnets, like those people linked with Bing and Google,” FDM said. “Site visitors from these IP addresses ended up always specified the accurate obtain website link.”

Future WEBINARLevel-Up SaaS Security: A Thorough Information to ITDR and SSPM

Keep in advance with actionable insights on how ITDR identifies and mitigates threats. Understand about the indispensable position of SSPM in ensuring your identification continues to be unbreachable.

Supercharge Your Competencies

“Intriguingly, this vulnerability was unknowingly fixed throughout a regimen website update in 2022,” it additional observed.

FDM has also unveiled a shell script for people to test for the existence of malware in their methods. It can be downloaded from right here.

But it really is worthy of pointing out that the scanner script does not take out the malware. Buyers who obtain the backdoor and the data stealer in their equipment are demanded to reinstall the program.

Discovered this write-up attention-grabbing? Observe us on Twitter  and LinkedIn to study far more distinctive information we article.


Some elements of this article are sourced from:
thehackernews.com

Previous Post: «beware: fake exploit for winrar vulnerability on github infects users Beware: Fake Exploit for WinRAR Vulnerability on GitHub Infects Users with VenomRAT
Next Post: Cyber Group ‘Gold Melody’ Selling Compromised Access to Ransomware Attackers cyber group 'gold melody' selling compromised access to ransomware attackers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.