Submitted via IRC for BoyceMagooglyMonkey
Microsoft said today that hackers compromised a font package installed by a PDF editor app and used it to deploy a cryptocurrency miner on users' computers.
The OS maker discovered the incident after its staff received alerts via the Windows Defender ATP, the commercial version of the Windows Defender antivirus.
Microsoft employees say they investigated the alerts and determined that hackers breached the cloud server infrastructure of a software company providing font packages as MSI files. These MSI files were offered to other software companies.
One of these downstream companies was using these font packages for its PDF editor app, which would download the MSI files from the original company's cloud servers during the editor's installation routine.
[...] Microsoft did not reveal the names of the two software companies involved in this incident. The OS maker says the compromise lasted between January and March 2018, and affected only a small number of users, suggesting the hacked companies aren't big names on the PDF software market.
Indicators of compromise are available in Microsoft's report on the attack, here.
(Score: 0) by Anonymous Coward on Saturday July 28 2018, @10:06AM (2 children)
Either a public facing system could sign packages, or the packages were unsigned.
In either case the company, and all those downstream in the case of unsigned packages, should be named and shamed.
(Score: 0) by Anonymous Coward on Saturday July 28 2018, @10:50AM (1 child)
From TFA:
(Score: 0) by Anonymous Coward on Saturday July 28 2018, @11:32AM
Lameness filter encountered. Post aborted!
Filter error: Missing Comment.