Windows attack: Poisoned BitTorrent client set off huge Dofoil outbreak, says Microsoft

General News

Summary

The Dofoil outbreak that attempted to infect over 400,000 Windows PCs within hours last week was caused by attack on an update server that replaced a BitTorrent client called MediaGet with a near-identical but back-doored binary.The MediaGet update poisoning, as Microsoft calls it, explains why the large-scale attempt to spread a cryptocurrency miner predominantly hit PCs in Russia, Turkey, and Ukraine."To set the stage for the outbreak, attackers performed an update poisoning campaign that installed a trojanized version of MediaGet on computers," the Windows Defender Research team wrote .The incident was notable to Microsoft because of the effort that went into laying the groundwork for the attack and the advanced techniques it used to conceal and maintain infections.The removal of the AV compatibility checks will mean that patches to mitigate the risk from Spectre and Meltdown attacks released since January will now be available to a wider range of PCs.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Consumer Software Desktop Software Mobile Apps

Linked Companies

BitTorrent Limited
$10M to $25M
Microsoft
$1B+