Cyber Hacking News

Fake Pokemon NFT game used to take over Windows devices

0

Hackers are using a well-crafted Pokemon NFT card game website to distribute the NetSupport remote access tool and gain control over victims’ devices.

The website “pokemon-go[.]io,” claims to be home to a new NFT card game built around the Pokemon franchise, providing users strategic fun together with NFT investment profits.

As both Pokemon and NFTs are very popular, it is easy for the operators of the malicious portal to attract the audience to the site through malspam, social media posts, etc.

The victims who click on the “Play on PC” button download an executable that looks like a legitimate game installer but, it actually installs the NetSupport remote access tool (RAT) on the victim’s system.

The analysts at ASEC who uncovered this operation reported that there was also a second site used in the campaign, at “beta-pokemoncards[.]io,”. However, it has since been taken offline.

This campaign’s activity initially appeared in December 2022, while earlier samples retrieved from VirusTotal showed that the same operators pushed a fake Visual Studio file instead of the Pokemon game.

The NetSupport RAT executable and its dependencies are installed in a new folder and are set to “hidden” to help evade detection from victims performing manual inspections on the file system.

Moreover, the installer creates an entry in the Windows Startup folder to ensure the RAT will execute upon system boot.

While NetSupport Manager is a legitimate software product, it is commonly used by threat actors as part of their malicious campaigns.

NetSupport Manager supports remote screen control, screen recording, system monitoring, remote system grouping for better control, and plenty of connectivity options, including network traffic encryption.

The consequences of such an infection are severe, mainly concerning unauthorized access to sensitive user data and downloading further malware.

Image Credits : Blockzeit

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Rackspace confirms Play ransomware gang behind recent breach

Previous article

Royal Mail stops international services after cyberattack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *