Readers like you help support my blog. When you make a purchase using links on our site, we may earn an affiliate commission! Thank you!

Saturday, April 4, 2020

Discord Turned Into an Account Stealer by Updated Malware

By Lawrence Abrams April 3, 2020 06:07 PM

A new version of the popular AnarchyGrabber Discord malware has been released that modifies the Discord client files so that it can evade detection and steal user accounts every time someone logs into the chat service.

AnarchyGrabber is a popular malware distributed on hacking forums and in YouTube videos that steals user tokens for a logged-in Discord user when the malware is executed.

These user tokens are then uploaded back to a Discord channel under the attacker's control where they can be collected and used by the threat actor to log in as their victims.

The original version of the malware is in the form of an executable that is easily detected by security software and only steals tokens while it is running.
Modify Discord client files to evade detection

To make it harder to detect by antivirus software and to offer persistence, a threat actor has updated the AnarchyGrabber malware so it modifies the JavaScript files used by the Discord client to inject its code every time it runs.

This new version is given the very original name of AnarchyGrabber2 and when executed will modify the %AppData%\Discord\[version]\modules\discord_desktop_core\index.js file to inject JavaScript created by the malware developer.

For example, the index.js file normally looks like the following image for an unmodified Discord client.
Unmodified index.js file

When AnarchyGrabber2 is executed, the index.js file will be modified to inject additional JavaScript files from a 4n4rchy subfolder as shown below.
AnarchyGrabber2 modified index.js file

With these changes, when Discord is started the additional malicious JavaScript files will be loaded as well.

Now, when a user logs into Discord, the scripts will use a webhook to post the victim's user token to a threat actor's Discord channel with the message "Brought to you by The Anarchy Token Grabber".
Stealing a Discord user token

MalwareHunterTeam, who found this new variant and shared it with us, told BleepingComputer that "skids are sharing them everywhere."

What makes these Discord client modifications such a problem is that even if the original malware executable is detected, the client files will be modified already.

As security software does such a poor job detecting these client modifications, the code will stay resident on the machine without the user even knowing their accounts are being stolen.
Discord needs to do client integrity checks

This is not the first time a Discord malware has modified the client's JavaScript files.

In October 2019, BleepingComputer broke the news that a Discord malware was modifying the client files to turn the client into an information-stealing Trojan.

At the time, Discord had stated that they would look into ways to prevent this from happening again, but unfortunately, those plans never happened.

The proper way these modifications can be detected is for Discord to create a hash of each client file when a new version is released. If a file is modified, then the hash for that particular file will change.

Discord can then perform a file integrity check on startup and if a file has been detected, display a message like the one below that was created by BleepingComputer.
Discord File Check Mockup

Until Discord adds client integrity into their client's startup, Discord accounts will continue to be at risk from malware that modifies the client files.

BleepingComputer has contacted Discord about this malware and the file integrity checks but has not heard back as of yet.

Friday, April 3, 2020

Zoom's Web Client is Down, Users Report 403 Forbidden Errors

By Sergiu Gatlan April 3, 2020 11:20 AM

Zoom users are currently reporting that they are unable to use the Zoom web client or start and attend webinars, with reports saying that the web client is throwing '403 Forbidden' errors.

Other reports mention time out errors saying that "Your connection has timed out and you cannot join the meetings. Verify your networkk connectivity and try again."

Based on user reports on DownDetector, Zoom users from the US East Coast and Western Europe are most affected by these ongoing issues,

According to the platform's status page, the Zoom web client is under maintenance and, as detailed on the company's dev forum, Zoom is "working to get the Zoom Web Client and Zoom Web SDK back online."
Zoom outage map (DownDeetector)

A Zoom spokesperson confirmed the web client outage, and advised users to download and install the desktop application until the issues are resolved.

"Our team is currently aware of issues with users joining Zoom meetings and webinars using Zoom’s web client," a statement from a Zoom spokesperson says.

"In the interim, we recommend downloading and installing Zoom from to connect to your meeting. We are working on it and will post further information and updates on shortly.

"Sorry for the inconvenience. Thank you very much for your patience."
Zoom timeout error (aleksandr.borovsky)

Software company Zoom provides users with a cloud-based communication platform that can be used for video conferencing, online meetings, and chat and collaboration via mobile, desktop, and telephone systems.

Zoom has seen a quick increase of new monthly active users since the start of 2020, with millions of employees and students who are now working and learning from home using the platform.

Zoom has gained around 2.22 million new users this year alone, while only 1.99 million were added last year. In total, it now has over 12.9 million monthly active users, with Bernstein Research analysts saying last month that Zoom saw a user growth of about 21% since the end of 2019 as reported by CNBC.

Facebook Messenger: Η desktop εφαρμογή είναι πλέον διαθέσιμη!

ByPohackontas  3 Απριλίου 2020, 15:50

Το Facebook Messenger μόλις κυκλοφόρησε μια desktop εφαρμογή για MacOS και Windows, η οποία παρέχει στους χρήστες τη δυνατότητα να συνομιλούν μέσω βίντεο από τον υπολογιστή τους, διατηρώντας έτσι την επικοινωνία και την επαφή τους με φίλους, οικογένεια και άλλα πρόσωπα σε κάθε γωνιά του πλανήτη.

Αυτή την περίοδο, οι άνθρωποι χρειάζονται και χρησιμοποιούν περισσότερο από ποτέ την τεχνολογία, τόσο για την δουλειά τους όσο και για να επικοινωνούν με άτομα από το επαγγελματικό και το προσωπικό τους περιβάλλον, ακόμα και αν δεν μπορούν να βγουν από το σπίτι τους. Ενδεικτικά, τον προηγούμενο μήνα σημειώθηκε περισσότερο από 100% αύξηση των χρηστών που χρησιμοποιούν τον browser του desktop τους για φωνητικές κλήσεις και βίντεο στο Messenger. Τώρα που υπάρχουν εφαρμογές για MacOS και Windows, έρχεται στο desktop σας η καλύτερη εκδοχή του Facebook Messenger, η οποία προσφέρει απεριόριστες και δωρεάν ομαδικές βιντεοκλήσεις.

Σε αυτό το σημείο, αξίζει να αναφερθούν ορισμένα highlights της νέας εφαρμογής Messenger:

Ομαδικές βιντεοκλήσεις σε μεγαλύτερη οθόνη: Έχετε τη δυνατότητα να επικοινωνήσετε με την οικογένεια και τους φίλους σας, να συμμετάσχετε σε ένα workout ή να ψυχαγωγηθείτε.

Εύκολη σύνδεση: Δεν χρειάζεται να γνωρίζετε το email ή τον αριθμό τηλεφώνου κάποιου, αφού οι φίλοι που έχετε στο Facebook έχουν Messenger.

Multitasking: Μπορείτε να έχετε εύκολη πρόσβαση στις συνομιλίες σας ενώ μπαινοβγαίνετε στην εφαρμογή, κάνοντας παράλληλα άλλα πράγματα στον υπολογιστή σας.

Ειδοποιήσεις: Μπορείτε να λαμβάνετε ειδοποιήσεις για νέα μηνύματα, ώστε να βρίσκετε απευθείας τη συζήτηση που αναζητάτε. Μπορείτε να επιλέξετε να απενεργοποιήσετε (mute) ή να αναβάλλετε (snooze) τις ειδοποιήσεις.
Οι συνομιλίες συγχρονίζονται στο κινητό και τον υπολογιστή σας: Με αυτόν τον τρόπο, δεν θα χάνετε ποτέ μια κλήση ή ένα μήνυμα, ανεξάρτητα από τη συσκευή που χρησιμοποιείτε.
Όλα όσα σας αρέσουν στο Messenger θα τα έχετε σε μεγαλύτερη οθόνη, συμπεριλαμβανομένων των GIF και του dark mode που υπάρχουν στη συνομιλία.

Μπορείτε να κατεβάσετε την εφαρμογή από το Microsoft Store ή το Mac App Store. Αυτή η desktop εφαρμογή του Facebook Messenger εγγυάται να διευκολύνει την καθημερινή σας επικοινωνία με οικεία και άλλα πρόσωπα, ώστε να συνεχίσετε να κοινωνικοποιείστε ακόμα και κατά το “social distancing” που επιβάλλουν οι υφιστάμενες συγκυρίες.

HBO: Δωρεάν πρόγραμμα 500 ωρών στα HBO NOW και HBO GO!

By Pohackontas
3 Απριλίου 2020, 15:20

Το HBO δήλωσε ότι θα παρέχει δωρεάν πρόγραμμα 500 ωρών στις υπηρεσίες streaming HBO NOW και HBO GO, χωρίς να απαιτείται συνδρομή, ξεκινώντας από σήμερα, Παρασκευή 3 Απριλίου. Με αυτόν τον τρόπο, το HBO δίνει στους ανθρώπους ακόμη περισσότερους λόγους να παραμείνουν στο σπίτι και να τηρήσουν τα μέτρα του “social distancing” που συνιστώνται, σε μία προσπάθεια να σταματήσει η εξάπλωση του COVID-19.

Στα σόου που μπορεί να παρακολουθήσει το κοινό δωρεάν μέσα από τις υπηρεσίες streaming HBO NOW και HBO GO συγκαταλέγονται μερικές από τις καλύτερες τηλεοπτικές εκπομπές που έγιναν ποτέ, όπως “The Sopranos” και “The Wire”, καθώς και άλλες πολύ καλές εκπομπές του HBO όπως οι “Veep” και “Six Feet Under”.

Κινηματογραφικές ταινίες όπως το “Pokémon Detective Pikachu”, το “Crazy, Stupid, Love” και οι “πολύτιμοι λίθοι” των καταλόγων, όπως το “Empire of the Sun”, περιλαμβάνονται στα docuseries, μαζί με το “McMillion $” και το “The Case Against Adnan Syed” ως δωρεάν προσφορές. Το κοινό που θέλει να παρακολουθήσει το αναμφισβήτητα καλύτερο σόου που έγινε ποτέ – The Wire – μπορεί να κατεβάσει τις εφαρμογές HBO NOW ή HBO GO ή να επισκεφτεί το ή το

Το HBO ανακοίνωσε ότι οι εκπομπές θα είναι διαθέσιμες για δωρεάν streaming από σήμερα. Αυτή η προσφορά που περιλαμβάνει δωρεάν πρόγραμμα 500 ωρών, παρέχεται για πρώτη φορά από το HBO. Ο κατάλογος του περιεχομένου του HBO που θα είναι διαθέσιμο για δωρεάν streaming χωρίς να απαιτείται συνδρομή περιλαμβάνει τα εξής:

9 Σειρές

• Ballers (5 Seasons)
• Barry (2 Seasons)
• Silicon Valley (6 Seasons)
• Six Feet Under (5 Seasons)
• The Sopranos (7 Seasons)
• Succession (2 Seasons)
• True Blood (7 Seasons
• Veep (7 Seasons)
• The Wire (5 Seasons)

10 docuseries και ντοκιμαντέρ

• The Apollo
• The Case Against Adnan Syed
• Elvis Presley: The Searcher
• I Love You, Now Die: The Commonwealth v. Michelle Carter
• The Inventor: Out for Blood in Silicon Valley
• Jane Fonda in Five Acts
• McMillion$
• True Justice: Bryan Stevenson’s Fight for Equality
• United Skates
• We Are the Dream: The Kids of the MLK Oakland Oratorical Fest

Και 20 κινηματογραφικές ταινίες της Warner Bros

• Arthur
• Arthur 2: On the Rocks
• Blinded By the Light
• The Bridges of Madison County
• Crazy, Stupid, Love
• Empire of the Sun
• Forget Paris
• Happy Feet Two
• Isn’t It Romantic?
• The Lego Movie 2: The Second Part
• Midnight Special
• My Dog Skip
• Nancy Drew and the Hidden Staircase
• Pan
• Pokémon Detective Pikachu
• Red Riding Hood
• Smallfoot
• Storks
• Sucker Punch
• Unknown

U.S. Government: Update Chrome 80 Now, Multiple Security Concerns Confirmed

 Davey Winder Senior Contributor

Update Google Chrome now, U.S. federal agency says. AFP VIA GETTY IMAGES

The Cybersecurity and Infrastructure Security Agency (CISA) has advised users to update Google Chrome as new high-rated security vulnerabilities have been found. Here’s what you need to know.

CISA, a standalone federal agency under the U.S. Department of Homeland Security (DHS) oversight, is responsible for protecting "the Nation’s critical infrastructure from physical and cyber threats." In an April 1 posting, CISA confirmed that Google Chrome version 80.0.3987.162 "addresses vulnerabilities that an attacker could exploit to take control of an affected system," be that Windows, Mac or Linux. It went on to state that it "encourages" users and administrators to apply the update.
Center for Internet Security also issues Google Chrome update advisory

It's not just CISA that is warning about the need to update Google Chrome. The Center for Internet Security (CIS) is a non-profit entity that works to safeguard both private and public organizations against cyber threats. In a multi-state information sharing and analysis center (MS-ISAC) advisory, it has also warned of multiple vulnerabilities in Google Chrome. The most severe of these could allow an attacker to achieve arbitrary code execution within the context of the browser. What does that actually mean? The answer is it depends upon the privileges that have been granted to the application. Still, in a worst-case scenario, the attacker would be able to view data, change data or delete data.
Are these vulnerabilities being exploited right now?

Although, at the time of writing, there have been no in-the-wild reports of these vulnerabilities being exploited by threat actors, that does not reduce the potential impact upon users who do not ensure the security update is applied as soon as possible. All it would take for an attacker to exploit the vulnerabilities is to get the user to visit, by way of a phishing attack or even redirection from a compromised site, a maliciously crafted web page. 

What is known about these high-rated security vulnerabilities in Google Chrome?

As is often the case, precise detail of the vulnerabilities is not being disclosed at this stage so as to allow the update to roll out to as many users as possible first. However, what is known is that there are three high-rated vulnerabilities discovered by external researchers that have been allocated Common Vulnerabilities and Exposures (CVE) identification numbers CVE-2020-6450, CVE-2020-6451 and CVE-2020-6452.

CVE-2020-6450 is described as being a use-after-free vulnerability in WebAudio, reported by Man Yue Mo of the Semmle Security Research Team on March 17.

CVE-2020-6451 is another use-after-free vulnerability in WebAudio, also reported by Man Yue Mo but five days earlier.

CVE-2020-6452 was reported, according to the Google Chrome update release blog, by a user just known as 'asnine' on March 9. This one is a heap-buffer overflow in the media component. 
MORE FROM FORBESGoogle Confirms 40,000 Nation-State Cyber Attack Warnings IssuedBy Davey Winder

A further five security vulnerabilities were discovered by the Google internal security team using a combination of internal audits and fuzzing. Fuzz testing is an automated method that prods code with unexpected inputs in order to reveal potential leaks or crashes that could be exploited by a threat actor. The precise nature of these vulnerabilities has not been disclosed by Google at this point.
Update your Google Chrome browser now to protect against these vulnerabilities

Google has said that the Chrome update will roll out over the coming days and weeks, but you really shouldn't wait for your browser to update automatically.

You can check to see what version you currently have by going to Help|About Google Chrome, which revealed that my copy had not been updated this morning, for example. The good news is that checking to see what version you have will also prompt an update to the latest version. You will need to relaunch the browser once the update has been installed and will then be protected against all of the vulnerabilities as mentioned earlier.