Supply Chain Compromise Leads to Trojanized Installers for Notezilla, RecentX, Copywhiz


On Tuesday, June 18th, 2024, Rapid7 initiated an investigation into suspicious activity in a customer environment. Their investigation identified that the suspicious behavior was emanating from the installation of Notezilla, a program that allows for the creation of sticky notes on a Windows desktop.

Installers for Notezilla, along with tools called RecentX and Copywhiz, are distributed by the India-based company Conceptworld at the official domain conceptworld[.]com. After analyzing the installation packages for all three programs, Rapid7 discovered that the installers had been trojanized to execute information-stealing malware that has the capability to download and execute additional payloads.

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • Building strong cyber security into ship design

    October 11, 2023

    As digitalization makes great strides in the shipping world, connectivity and system integration expose ships to growing cyber risks. This means that cyber security must be engineered into the design of every new vessel. Suppliers must deliver secure systems, and yards must combine these systems into a secure, painstakingly documented overall concept that provides a strong ...

  • One of the largest T-Mobile authorized retailers had 90GB of info leaked, including customer data

    September 23, 2023

    T-Mobile is often in the news for the wrong reasons. Yesterday, a glitch in the company’s system showed personal customer information to the wrong account holders. And now, there is fear that freshly leaked data that is available online could help bad actors gain access to sensitive information. In T-Mobile’s defense, the carrier cannot be blamed ...

  • HWL Ebsworth hack: 65 Australian government agencies affected by cyber-attack

    September 18, 2023

    Sixty-five Australian government departments and agencies were victims of the cyber-attack on legal firm HWL Ebsworth, the national cybersecurity coordinator has revealed. In a speech on Monday, Air Marshal Darren Goldie also revealed that some people and clients with personal information exposed in the hack have yet to be informed. The Russian-linked ALPHV/BlackCat ransomware group hacked the law ...

  • Kaspersky reveals three-year long suspected supply chain attack targeting Linux

    September 12, 2023

    UPDATE 13.09.2023. Free Download Manager team issued an official statement regarding this incident. Kaspersky unveiled a malicious campaign in which an installer of the Free Download Manager software was employed to disseminate a Linux backdoor for a minimum of three years. Researchers discovered that victims were infected when they downloaded the software from the official website, ...

  • Russia linked hackers hit UK Ministry of Defence as security secrets leaked

    September 2, 2023

    Top secret security information on British military and intelligence sites has been leaked online by hackers linked to Russia. They released thousands of pages of data which could help criminals get into the HMNB Clyde nuclear submarine base, the Porton Down chemical weapon lab and a GCHQ listening post. Information about high-security prisons and a military ...

  • UK: Metropolitan Police on red alert after details of officers and staff hacked in massive security breach

    August 26, 2023

    The Metropolitan Police were on red alert tonight after details of officers and staff were hacked in a massive security breach. All 47,000 personnel were warned of the risk their photos, names and ranks had been stolen when cyber crooks penetrated the IT systems of a contractor printing warrant cards and staff passes. Information taken also ...