That PowerShell 'fix' for your root cert 'problem' is a malware loader in disguise
ID: 622040ef-acce-5958-a23d-1411510883c4
STIX ID: report--622040ef-acce-5958-a23d-1411510883c4
Feed Name: The Register (Security)
Threat Score
Proofpoint reported multiple active criminal campaigns (TA571, ClearFix, ClearFake) using fake Chrome/Word/OneDrive error pop-ups and clipboard-based PowerShell instructions—sometimes delivered via blockchain-hosted scripts (EtherHiding)—to trick users into running commands that download loaders and stealers (Lumma, Vidar, Amadey, JaskaGo, etc.) and can lead to ransomware; campaigns have involved large-scale phishing and remain active.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
