Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Tweak it or the bunny gets it

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » February 2013 » Cyber-attackers turn NVIDIA tool into an accomplice

Cyber-attackers turn NVIDIA tool into an accomplice


Contributed by: Email on 02/28/2013 04:07 PM [ comments Comments ]


Virus experts at Sophos made a surprising discovery in their analysis of a targeted cyber attack. A specially crafted RTF document was taking advantage of a vulnerability in Word to execute a tool from NVIDIA's graphics card drivers on the victims' computers. The executable file, called nv.exe, is digitally signed – and is, in fact, the original file with no changes.

The reason for this method became clear after the NvSmartMax.dll library, which was copied with both the Word document and the .exe file onto computers, was analyzed: that library was home to the actual malicious code that set up a permanent backdoor. The malicious functions in the library were executed by the nv.exe file signed by NVIDIA.

The attackers took advantage of the fact that executable files first look for libraries in their own folder. In this case, nv.exe therefore tries to execute functions from its DLL but, instead, finds and uses an evil twin first. The attackers may have been using the signed binary as a detour in order to help their malicious code slip past any anti-virus software that might be installed.

The prepared Word document consists of a statement from the Tibetan Youth Congress, a non-governmental organization that works for Tibetan independence, which suggests that this cyber-attack was once again targeting pro-Tibet groups.






« Kelihos botnet taken down live on stage · Cyber-attackers turn NVIDIA tool into an accomplice · New technology turns your car into a smartphone accessory »




Comments
comments powered by Disqus

MajorGeeks.Com » News » February 2013 » Cyber-attackers turn NVIDIA tool into an accomplice

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition