Fake VPN checker tool lets hackers bypass antivirus protections

  • Attackers use fake Fortinet dialogs and social engineering to trick users into executing malware
  • Cache smuggling hides malware in browser cache, bypassing download and PowerShell detection tools
  • Malware is extracted from fake image files and deployed as FortiClientComplianceChecker.exe

Hackers are using a combination of social engineering, cache smuggling, identity theft, and straight-up bluffing, to bypass common security protections and deploy malware onto victim’s computers, experts have said.

Security researchers Expel, as well as an independent researcher with the alias P4nd3m1cb0y, observed websites pretending to be a pop-up dialog from Fortinet VPN’s “Compliance Checker”.

There seems to be no such thing, other than the ability to configure the FortiClient Compliance Profile within FortiOS. In any case, that dialog instructs the victim to copy what appears to be a path to a file installed on the hard drive, and paste it in File Explorer.

Used by ransomware actors

The path is actually padded with more than 100 spaces, to hide its true purpose – to run a PowerShell command. At the same time, the phishing website executed a JavaScript that instructed the browser to fetch an image and cache it on the file system. This file is not an actual image, but rather hidden malware.

“This technique, known as cache smuggling, enables the malware to bypass many different types of security products,” the researchers explained.

“Neither the webpage nor the PowerShell script explicitly download any files. By simply letting the browser cache the fake “image,” the malware is able to get an entire zip file onto the local system without the PowerShell command needing to make any web requests.”

“As a result, any tools scanning downloaded files or looking for PowerShell scripts performing web requests wouldn’t detect this behavior.”

The script then scans each cache file for content that’s actually a .ZIP file stored in the fake image, and extracts it to FortiClientComplianceChecker.exe – the actual malware. There was very little talk about who the attackers were, or the victims, but apparently some ransomware actors have already started deploying this tactic in their attacks.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Google’s Pixel Watch 3 and Anker’s two-headed USB-C cable are our favorite deals this week

Google’s last-gen Pixel Watch 3 is on sale for $199.99 ($100 off) for a limited time. There are plenty of good smartwatches out there, and...

Ayaneo Phone confirmed in a teaser featuring retro Remake branding

Ayaneo is best known for its retro gaming handhelds, but the company has now confirmed its first phone will be coming soon. Ayaneo briefly...

LG’s brilliant B5 OLED TV is already down to just $530 for Black Friday

Best Buy’s latest doorbuster deal nets you a cool $770 off the regular price. | Image: The Verge Best Buy’s early Black Friday deals are...

AMD’s 780G Chipset Test and Review

Editor’s Note: This is a legacy article, originally published March 4, 2008. While pricing and availability details may be outdated, the test results and...

The SSD Endurance Experiment: Only Two Remain After 1.5PB

Editor’s Note: This is a legacy article, originally published September 19, 2014. While pricing and availability details may be outdated, the test results and...

Trump’s FCC is officially moving to make it easier for internet companies to charge hidden fees

The Republican-led FCC has voted on and approved a proposal that would make it harder for consumers to receive itemized bills with accurate information...

Creative Labs is crowdfunding a modular Sound Blaster audio hub

Creative Labs, the maker of Sound Blaster audio cards, has launched a Kickstarter for a modular audio hub called Sound Blaster Re:Imagine. The universal...

Today’s best iPad deals include the standard iPad with the A16 chip for $299

Apple's most recent iPad release is the iPad Pro with the new M5 chip (we called it "perhaps the most impressive piece of hardware...

The IOC and Saudi Arabia call it quits on their Olympic esports partnership

The esports partnership between the International Olympic Committee (IOC) and Saudi Arabia is no more. On Thursday, the IOC said that it and the...

Are you a YouTube TV subscriber looking for ESPN and ABC? Here are your options

SOPA Images via Getty Images If you're a YouTube TV subscriber, you may have noticed that ABC, ESPN...