1 min read

Hackers Are Using NFT Excitement to Trick Users

Researchers from Fortinet are warning of a new threat to be on the lookout for.

Right now, NFTs are all the rage.  Everyone is talking about them, and many are excited about them.  Hackers have been quick to take advantage of that fact, and the Fortinet researchers have stumbled across a poisoned spreadsheet that purports to contain information about NFTs.

The spreadsheet actually quietly deploys a malware strain called BitRAT when opened.

BitRAT is a particularly nasty strain of malware that first appeared for sale on the Dark Web back in late 2020.  It is notable because it can bypass User Account Control (UAC), which is a Windows feature designed to prevent unauthorized access to the OS.

Once installed on a target system BitRAT can steal login credentials from browsers and other applications. It can log keystrokes and upload or download files which makes it more than capable of installing other forms of malware once the beachhead has been established.

It’s too early to say yet whether NFTs are here to stay or if they’re just a flash in the blockchain pan.  Either way, if they are generating buzz and excitement around the world, hackers will continue to exploit that excitement.

As the Fortinet researchers put it:

“Be mindful that attackers often use attractive and trendy subjects as lures. As NFTs become increasingly popular, they will be used to entice victims into opening malicious files or clicking on malicious links.”

The best thing you can do is to educate your employees and inform them of the threat.  Remind everyone you know that no matter how exciting the topic might be, it’s never a good idea to open files from untrusted sources or click on links embedded in emails.  If you need to go to a website open a new browser tab and manually type in the URL.  Better safe than sorry.

Used with permission from Article Aggregator

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

The first AI-run ransomware attack wasn't the story. What followed, and what it means for every organization deploying AI agents, is.

Read the full blog
Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT provider's response time promise is only worth what they actually deliver. Here's how to read your SLA, what good looks like, and how to...

Read the full blog
Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Most businesses treating Copilot and ChatGPT as substitutes are using at least one wrong. Here's what each is built for and how to choose.

Read the full blog

Google Soon Informing Users About What Data Apps Collect

A new Data Safety section is coming to the Google Play Store, providing transparency on what data your apps collect for better privacy awareness.

Read the full blog

Microsoft Teams Gets Optimizations To Use Less Resources

Do you use Microsoft Teams and do you have an older PC that struggles with Teams video meetings? If so there’s good news.

Read the full blog

Why Your Business Should Use a Password Manager

To the average person, it’s too easy to forget a password and leave themselves vulnerable to account lockout, which can end up being a real hassle.

Read the full blog