• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ukrainian hacker suspected to be behind "free download manager" malware

Ukrainian Hacker Suspected to be Behind “Free Download Manager” Malware Attack

You are here: Home / General Cyber Security News / Ukrainian Hacker Suspected to be Behind “Free Download Manager” Malware Attack
September 21, 2023

The maintainers of No cost Obtain Supervisor (FDM) have acknowledged a security incident relationship again to 2020 that led to its web-site getting made use of to distribute destructive Linux software program.

“It appears that a particular web web site on our site was compromised by a Ukrainian hacker group, exploiting it to distribute malicious software,” it stated in an warn past week. “Only a modest subset of users, specially all those who tried to obtain FDM for Linux in between 2020 and 2022, ended up most likely exposed.”

Considerably less than .1% of its visitors are believed to have encountered the issue, introducing it may well have been why the issue went undetected until finally now.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The disclosure arrives as Kaspersky disclosed that the project’s site was infiltrated at some stage in 2020 to redirect pick Linux customers who tried to obtain the software program to a destructive website hosting a Debian deal.

The offer was even more configured to deploy a DNS-based mostly backdoor and in the long run serve a Bash stealer malware capable of harvesting sensitive facts from compromised techniques.

FDM claimed its investigation uncovered a vulnerability in a script on its web-site that the hackers exploited to tamper with the obtain website page and direct the internet site website visitors to the faux area deb.fdmpkg[.]org hosting the destructive .deb file.

“It had an «exception list» of IP addresses from different subnets, like those people linked with Bing and Google,” FDM said. “Site visitors from these IP addresses ended up always specified the accurate obtain website link.”

Future WEBINARLevel-Up SaaS Security: A Thorough Information to ITDR and SSPM

Keep in advance with actionable insights on how ITDR identifies and mitigates threats. Understand about the indispensable position of SSPM in ensuring your identification continues to be unbreachable.

Supercharge Your Competencies

“Intriguingly, this vulnerability was unknowingly fixed throughout a regimen website update in 2022,” it additional observed.

FDM has also unveiled a shell script for people to test for the existence of malware in their methods. It can be downloaded from right here.

But it really is worthy of pointing out that the scanner script does not take out the malware. Buyers who obtain the backdoor and the data stealer in their equipment are demanded to reinstall the program.

Discovered this write-up attention-grabbing? Observe us on Twitter  and LinkedIn to study far more distinctive information we article.


Some elements of this article are sourced from:
thehackernews.com

Previous Post: «beware: fake exploit for winrar vulnerability on github infects users Beware: Fake Exploit for WinRAR Vulnerability on GitHub Infects Users with VenomRAT
Next Post: Cyber Group ‘Gold Melody’ Selling Compromised Access to Ransomware Attackers cyber group 'gold melody' selling compromised access to ransomware attackers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.