Organizations in the Middle East Targeted By Malware Impersonating Palo Alto GlobalProtect VPN



social-engineering-2A social engineering campaign is targeting entities in the Middle East using malware that impersonates Palo Alto Networks’ GlobalProtect VPN, according to researchers at Trend Micro. 

The malware is likely distributed via phishing attacks against users who are seeking to install GlobalProtect. Once the malware is installed, it poses as a company VPN portal while it conducts malicious activities.

“Written in C#, this malware boasts a range of capabilities, including the ability to execute remote PowerShell commands, download and execute additional payloads, and exfiltrate specific files from the infected machine,” the researchers write. “These functions highlight the malware's potential to cause significant damage and disruption within targeted organizations.”

Trend Micro says organizations should implement the following security best practices to defend against these attacks:

  • “User awareness and training: Conducting regular training sessions on the various types of social engineering attacks, providing updates on new tactics and trends in social engineering, and educating employees to recognize common red flags can help prevent users from falling victim to social engineering lures
  • Principle of least privilege: Granting employees access only to the data and systems they need for their roles minimizes the chance of attackers gaining access to vital information even during a successful breach
  • Email and web security: Organizations should deploy robust email and web security solutions to filter and block malicious and suspicious content
  • Incident response plan: A well-defined incident response plan is crucial for organizations to be able to handle social engineering attacks. This includes the immediate steps to contain and mitigate the threat”

New-school security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Trend Micro has the story.


Free Ransomware Simulator Tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

KnowBe4’s "RanSim" gives you a quick look at the effectiveness of your existing network protection. RanSim will simulate 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the install and run it 
  • Results in a few minutes!

Get RanSim!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/ransomware-simulator



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews