Security News Big Surprise: Chinese PUPs Deliver Backdoored Drivers

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
A driver secretly installed via PUPs packages for Chinese software contain backdoors enabling a third-party to load unsigned drivers or to execute code with higher privileges on a Windows machine.

The backdoor was discovered by Malwarebytes researchers part of various bundled software packages pushed by at least two major PUP bundler networks.
The PUP installer drops a series of 7-ZIP archives on each victim's computer. These archives contain the PUP application's resources, including a 32 and 64-bit version for a driver that is forcibly and silently installed on the user's computer without his knowledge.

Backdoor enables two possible actions

More infos in the link above
 
5

509322

scary,
There are many dangerous free programs offered on giveaway websites, As if everything is normal, even they come signed with certificate, LOL.
even, there are theories that some trust programs, they already do it.
you can not trust anyone but Live with worries, Is bad for health.
giphy.gif
dolor-de-cabeza-intenso-300x214.jpg

dos+elf+laugh.gif

No one has to live that way anymore... just use default-deny\system lock-down instead of default-allow.
 

Entreri

Level 7
Verified
May 25, 2015
342
No surprise. I wouldn't even trust Chinese "security/AV" companies. Once IBM sold their great laptop brand to Lenovo, lol.

If I was going to build a business, I would only use Apple products.

I just bought a cheap Motorola smartphone, no way will I ever do banking on it...
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
A driver secretly installed via PUPs packages for Chinese software contain backdoors enabling a third-party to load unsigned drivers or to execute code with higher privileges on a Windows machine.

The backdoor was discovered by Malwarebytes researchers part of various bundled software packages pushed by at least two major PUP bundler networks.
The PUP installer drops a series of 7-ZIP archives on each victim's computer. These archives contain the PUP application's resources, including a 32 and 64-bit version for a driver that is forcibly and silently installed on the user's computer without his knowledge.

Backdoor enables two possible actions

More infos in the link above
Not surprising in the least, and that's all I will say on this seeing we have so many Chinese AV software
fans here. :rolleyes:
Cool Share Solar :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top