Porthos
Well-Known Member
- Reaction score
- 14,163
- Location
- San Antonio Tx
https://www.bleepingcomputer.com/ne...somware-windows-customization-tool-exploited/
Windows customization tool exploited in attack
According to the SoftService incident report, the attackers exploited a DLL hijacking vulnerabilitie in the legitimate Rainmeter application to deploy their ransomware.
Rainmeter is a legitimate Windows customization tool that loads a Rainmeter.dll when launched.
During the attack, the threat actors replaced the legitimate Rainmeter.dll with a malicious version compiled from the source code to deploy the ransomware.