
Mobile Malware Alert: Anatsa Targets Travel Firms for Financial Fraud
Overview A sophisticated strain of mobile banking malware known as Anatsa has resurfaced, now targeting travel firms and their customers for financial fraud. Anatsa differs…
SFXs are a method of compressing files that, when opened, will extract the file’s contents automatically. They’re often used legitimately to compress and share large files with users who do not have software such as WinZIP/WinRAR, which can extract compressed files. SFXs are often delivered through social engineering and phishing techniques to trick a victim into opening the file.
Recently CrowdStrike has observed SFXs being used to deliver and deploy malware on targets. If opened by a victim, the malware will be extracted and immediately executed, leaving victims and anti-virus systems with little time to respond. CrowdStrike reported a case study where a threat actor utilised an SFX to abuse various Windows applications to create a backdoor on the victim’s machine. The severity of these attacks will depend on the sophistication of the malware or the aim of the code within; however, it could result in data breaches, system compromise, financial loss and reputational damage.