Infostealer infection through fake Windows Update Error Fix
An infostealer infection effecting through a fake Windows update error fix with a premade script is analysed by our experienced colleagues.
Our S.O.S. line:
+49 89 262 025954
Our team of experts is ready to assist your organization in the event of a cyberattack.
detailsCyber Threat Intelligence + Incident Response + Security Operations Center Csaba Krasznay todayJune 20, 2024

One of the most widespread cybercrimes in recent years is Business Email Compromise. The execution of this type of fraud is apparently very simple.
This type of fraud has been much talked about in the media and by the police in every country. However, not only does the FBI news (https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-scams-and-crimes/business-email-compromise) show that there are more cases every week. Our colleagues at White Hat IT Security are also under the impression that the number of BEC scams has increased significantly in recent months. In fact, industry surveys such as the Abnormal Threat Report (https://abnormalsecurity.com/blog/bec-vec-attacks) and Perception Point’s 2024 Annual Report (https://perception-point.io/resources/report/2024-annual-report/) confirm our impressions: the number of Business Email Compromise attacks has risen significantly over the past year. In addition, of course, the ENISA Threat Landscape (https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023) also dedicates a specific subsection to this type of fraud, which shows its importance at European level.
Therefore, there is problem. But what is the reason for the upsurge in this type of attack? Let’s take a look at the trends that are helping cybercriminals. First, to be convincing, an attacker needs deep information about the life of the organisation. You need to know who the company does business with, what transactions are in progress, which can be diverted, how employees communicate with each other. This information can typically be found in internal company emails, which attackers have a tendency to access. For example, at the time of writing, the CISA Known Exploited Vulnerabilities Catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=exchange&field_date_added_wrapper=all&sort_by=field_date_added&items_per_page=20&page=1) lists 16 vulnerabilities against Microsoft Exchange Server that could potentially be exploited to gain access to a company’s entire e-mail database. But the data stolen in ransomware attacks can also provide a rich source of information for establishing appropriate communications.
Once you have the data, you “just” have to process it. Let’s not forget that an email account can contain terabytes of unstructured data that would be difficult to interpret with human skills alone. But this is where artificial intelligence can help enormously! All you have to do is feed the data into the large language model (LLM, like ChatGPT), which then extracts the important information and uses it to create spearphishing emails that can be used in an attack. And it can do all this in any language. But that’s just the written part! With the proliferation of deep fake technologies, creating faces and voices is not impossible. In February 2024, for example, several press articles referred to a case in Taiwan where a financial manager was duped by fraudsters in a video call (https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html), such that the victim was the only real person in the call, everyone else was a deep fake persona. Although the case is treated with minor reservations, it is a warning sign that $25 million in damages were incurred after this incident.
What is the conclusion? That Business Email Compromise fraud, however primitive it may seem, is a serious threat to companies. It is therefore essential that all potential victims are aware of this type of fraud and, if they detect even the slightest sign of abuse, should check the authenticity of the transactions they are expecting to receive. From a technical point of view, email filtering solutions such as Microsoft Defender for Office 365 (https://learn.microsoft.com/en-us/defender-office-365/anti-phishing-protection-about) will have a good chance of filtering out even spearphishing emails based on their characteristics. However, there is no effective protection against deep fakes for the time being. In this case, only healthy paranoia and vigilance can help. And if problem does happen, our incident management team is available to ensure that at least the extent of the problem remains manageable. Incident Response Services – White Hat IT Security
Written by: Csaba Krasznay
Cyber Threat Intelligence White Hat / June 12, 2024
An infostealer infection effecting through a fake Windows update error fix with a premade script is analysed by our experienced colleagues.
Penetration Testing WhiteHat / August 28, 2026
This week’s CVE of the Week is CVE-2026-24301, also known as CoSnitch, an exfiltration method in Microsoft Copilot that could allow an unauthorized attacker to steal sensitive information and data. With a CVSS score of 8.8, deserves serious attention. It is a combination of three different vulnerabilities that could allow an attacker to pull data ...
Cyber Threat Intelligence WhiteHat / August 6, 2026
What is Cyber Threat Intelligence, and why does it matter? Learn the CTI lifecycle, intelligence types, and how threat intelligence helps prevent cyberattacks.