Notice from InfoSec

On January 5, 2022, a new attack campaign was reported that leverages the legitimate Atera RMM software to gain initial access to target machines.

An infection begins with installing Atera software on a target machine. Atera is legitimate enterprise RMM software that can install an agent and assign the endpoint to a particular account with an .msi file that includes the owner’s email address. The attackers did this with a temporary email address, and the downloadable file is disguised as a Java installation — a method seen in earlier Zloader campaigns.

Eisenkraft (A Company that we exploited) says the team is unsure how attackers deploy Atera onto victim devices in this campaign; however, in earlier Zloader campaigns, the operators lured victims by playing part of an adult film. After a few seconds, the video stopped and a message would say their Java needed to be updated. They were prompted to download a “Java” installation, which was a trial version of Atera that enabled attackers to send files to the machine and run them, he explains.

After the software is on the machine, the attacker uploads and runs two .bat files onto the device using the “Run Script” function. One is used to modify Windows Defender preferences, and the other is used to load the rest of the malware. In this stage, scripts add exclusions to Windows Defender and disable tools that could be used for detection and investigation.

Get In Touch

Share On Social Media

Other Recent Blog Articles

Podcast: Returning Special Guest Erik Swanson of Cardinal Services

April 22, 2024

We’re thrilled to welcome Erik Swanson of Cardinal Services as our returning special guest. Erik brings a wealth of expertise in the intersection of IT and HR, shedding light on…

Read More

Wells Fargo is back in the News!

April 22, 2024

Wells Fargo is back in the news, but this time it is because of a data breach. Banking giant Wells Fargo has sent a data breach notice to some customers.…

Read More

Safeguard Your Small Business: The Vital Role of IT Managed Services in Preventing Catastrophic Outages

April 12, 2024

In the fast-paced world of modern business, the reliance on technology has never been more significant. However, with this reliance comes the looming threat of cyberattacks, as evidenced by the…

Read More