Did you know Hackers Are Now Hiding Malware in Images Sent on Emails to Steal Credentials
Hackers have advanced their techniques to bypass the security system to
steal user credentials, but the primary method to do it is through
emails. HP Wolf security threat insights report shows
that two new malwares named obj3ctivityStealer and VIP Keylogger are
going around on emails where they are hidden in images. Gmail and
Outlook users have been warned to beware of them and not click any links
in the email they don't know. These two malware threats are hidden
inside images which users click on unknowingly.
Security
researchers have said that obj3ctivityStealer and VIP Keylogger are
using the same techniques to exploit the system and steal information.
The malware named obj3ctivityStealer steals credit card data and other
account credentials of the users, while VIP Keylogger can steal account
credentials from a lot of sources like clipboard data and apps, and can
also record keystrokes.
The malware obj3ctivityStealer is in images with quotation requests. On the other hand, malware VIP Keylogger appears in images related to purchase orders and invoices to victims. The most accessed image with VIP Keylogger malware has 29,000 views. As attackers are hiding these malicious codes in images by hosting them on legitimate websites, they can easily bypass security which rely on reputation checks.