Microsoft finds hackers using unknown Windows security flaws

digital data lock on screen
(Image credit: Shutterstock)

Microsoft has revealed a potentially damaging new spyware campaign targeting victims around the world.

In a blog post, Microsoft claims that an Austrian company posing as a risk analysis and business intelligence service provider is in fact, a spyware developer responsible for Subzero, malware used against endpoints belonging to law firms, banks, and consultancy firms in the UK, Austria, and Panama.

The company, known as DSIRF, was found allegedly abusing zero-days exploits in both Windows and Adobe Reader to provide its customers with remote code execution capabilities, among other things. Before identifying the threat actor, Microsoft was tracking it under the codename KNOTWEED.

Commercial spyware

Before identifying the threat actor, Microsoft was tracking it under the codename KNOTWEED, and says it has now patched the vulnerabilities abused by DSIRF.

“MSTIC [Microsoft Threat Intelligence Center] has found multiple links between DSIRF and the exploits and malware used in these attacks. These include command-and-control infrastructure used by the malware directly linking to DSIRF, a DSIRF-associated GitHub account being used in one attack, a code signing certificate issued to DSIRF being used to sign an exploit, and other open-source news reports attributing Subzero to DSIRF,” Microsoft said in the blog. 

As spotted by The Verge, Microsoft’s report was published while the company testified in front of the House Intelligence Committee, on “Combatting the Threats to U.S. National Security from the Proliferation of Foreign Commercial Spyware”. In the testimony, submitted in written form, Microsoft argues that in the past decade, there’s been a boom of commercial entities developing, and selling, spyware, to repressive regimes around the world. 

“Over a decade ago, we started to see companies in the private sector move into this sophisticated surveillance space as autocratic nations and smaller governments sought the capabilities of their larger and better resourced counterparts,” it says in the testimony.

“In some cases, companies were building capabilities for governments to use consistent with the rule of law and democratic values. But in other cases, companies began building and selling surveillance as a service ... to authoritarian governments or governments acting inconsistently with the rule of law and human rights norms.”

Microsoft has urged the U.S. to classify spyware as a “cyberweapon”.

  • Keep your online activities to yourself with the best firewalls around

Via: The Verge

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A red padlock image against a digital map of the earth in blue.
Midnight Blizzard hacking group hijacks RDP proxies to launch malware attacks
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
Russia
Major Russian hacking group shifts focus to US and UK targets
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over