{"id":7394,"date":"2021-06-24T09:05:05","date_gmt":"2021-06-24T13:05:05","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=7394"},"modified":"2021-07-23T14:05:49","modified_gmt":"2021-07-23T18:05:49","slug":"attackers-are-using-call-centers-to-hack-victims-files","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/attackers-are-using-call-centers-to-hack-victims-files\/","title":{"rendered":"Attackers Are Using Call Centers To Hack Victims Files&nbsp;"},"content":{"rendered":"\n<p>Microsoft&#8217;s cybersecurity researchers are now warning users about BazarCall, a criminal group that uses call centers to infect PCs with malware called BazarLoader &#8211; a malware loader used to spread ransomware.<\/p>\n\n\n\n<p>Brad Duncan of Palo Alto Networks recently detailed the group&#8217;s plans.<\/p>\n\n\n\n<p>As he describes, the malware provides backdoor access to an infected Windows device.<\/p>\n\n\n\n<p>After a computer is infected, criminals use this backdoor access to send follow-up malware, scan the environment, and exploit other vulnerable machines on the network.<\/p>\n\n\n\n<p>The attack starts with phishing emails reminding the victim that a trial subscription has expired and that they will automatically be charged a monthly fee unless they call to cancel.<\/p>\n\n\n\n<p>When recipients call the number, a fraudulent call center is run by the attackers, who advise them to visit a website and download an Excel file to cancel the service.<\/p>\n\n\n\n<p>The group&#8217;s activities are now under the radar of Microsoft&#8217;s Security Intelligence Team.<\/p>\n\n\n\n<p>Microsoft has released a GitHub page to share details about the BazarCall campaign, and the tech giant is also updating details about phishing emails, the use of Cobalt Strike for cross-movement, malicious Excel macros, Excel delivery techniques, and the use of Windows NT Directory Services, or NTDS, to steal AD files.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-warns-now-attackers-are-using-a-call-centre-to-trick-you-into-downloading-ransomware\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in ZDNet.<\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft warns users about BazarCall, a criminal group that uses call centers to infect PCs with malware called BazarLoader.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-7394","post","type-post","status-publish","format-standard","hentry","category-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=7394"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7394\/revisions"}],"predecessor-version":[{"id":7433,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7394\/revisions\/7433"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=7394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=7394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=7394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}