{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreihmqoel2vzerrwr35qcnvzuoolpilj645rupp7ltptbfkc6z2kinu",
"uri": "at://did:plc:wnd7xrumusq5uayjfi2pgfno/app.bsky.feed.post/3mgamrbybhoz2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreifxftj4lv7244m7rzcvypdy3zazmf53x7ukllxka7c2kvoez32xrm"
},
"mimeType": "binary/octet-stream",
"size": 488762
},
"description": "TL;DR\n\n * Microsoft Defender identifies phishing campaign using ScreenConnect, Tactical RMM, and Mesh Agent via signed MSI packages in February 2026\n * Phishing campaign impersonates Zoom and Google Meet waiting rooms to deploy Windows remote monitoring malware\n * Trail of Bits releases mquire, a Linux memory forensics tool that analyzes dumps without debug symbols using BTF and kallsyms\n\n\nđ 2.4M Windows Devices Pwned by Revoked-Cert Malware: TrustConnectâs Phishing Campaign Hits U.S. Enterpris",
"path": "/2026-03-04-176663929545644669294197706391743750424/",
"publishedAt": "2026-03-04T15:43:19.000Z",
"site": "https://espresso.cafecito.tech",
"textContent": "### TL;DR\n\n * Microsoft Defender identifies phishing campaign using ScreenConnect, Tactical RMM, and Mesh Agent via signed MSI packages in February 2026\n * Phishing campaign impersonates Zoom and Google Meet waiting rooms to deploy Windows remote monitoring malware\n * Trail of Bits releases mquire, a Linux memory forensics tool that analyzes dumps without debug symbols using BTF and kallsyms\n\n\n\n* * *\n\n## đ 2.4M Windows Devices Pwned by Revoked-Cert Malware: TrustConnectâs Phishing Campaign Hits U.S. Enterprises\n\n> 2.4M Windows boxes got pwned by a fake Zoom invite đ€ŻâŠ and the malware was signed by a certificate REVOKED 2 weeks before it ran. đ Microsoft Defender saw it. The system STILL trusted it. They didnât just hack youâthey hacked the trust chain. Your IT teamâs âcertificate updatesâ are a suggestion. Your data? Not so much. Whoâs really in charge of your security: your vendor⊠or the guy who revoked the cert but didnât tell your network?\n\nYour âurgent Teams inviteâ just invited three uninvited guestsâScreenConnect, Tactical RMM, and Mesh Agentâstraight into HKLM, LocalSystem, and (soon) your HR exit interview. Microsoft Defender caught the party in February, but the hangover is forever.\n\n### How the sausage gets stuffed\n\n 1. Spoofed Teams/Zoom email â unsigned MSI pretending to be a PDF.\n 2. msiexec.exe fires, drops three binaries, registers itself as a Windows service under LocalSystem.\n 3. ConnectWise cert was revoked mid-month; nobody told the installerâexecution barrels on like a caffeine-addled intern.\n 4. Encoded callback tokens phone home to rmm-stage.trustconnectsoftware.com; AES-256 over TLS 1.2 keeps the snoop cozy.\n\n\n\n### Pain by numbers\n\n * **Persistence** : 3 fresh HKLM service keys â manual deletion hell, reboot loops, weekend ruined.\n * **Exfiltration surface** : MeshAgent can hoover %UserProfile% â goodbye payroll spreadsheets, hello dark-web coupon codes.\n * **Certificate hygiene** : 1 revoked 2022 ConnectWise sig still trusted on execution â your PKI is decorative tinsel.\n * **Network IOCs** : 2 IPs, 2 domains â block âem or prepare apology letters for 10 000 employees.\n\n\n\n### What âenterprise defenseâ looks like when the budgetâs gone\n\n * Group Policy to nuke msiexec from Downloadsâzero licensing fee, 100 % middle-finger to the attacker.\n * DNS sinkhole the C2 domains for the cost of one fancy latte per month.\n * Scheduled script that audits HKLM\\Services for new kids on the blockâPowerShellâs free, your sanity isnât.\n\n\n\n### Forecast: same crap, new wrapping\n\n * **Next 30 days** : signed MSI variants with fresh certs â your whitelist becomes a welcome mat.\n * **Mid-2026** : OAuth device-code grafted onto MeshAgent â phishing 2.0 harvests tokens while you beg for MFA budget.\n * **Late 2026** : vendor pitch âAI-powered MSI Sandboxing Platinumâ at $250 k/year â repeat cycle, rinse, cry.\n\n\n\nClose the inbox, open the firewall, and remember: if it ends in .msi and smells like productivity, itâs probably plotting your unemployment.\n\n* * *\n\n## đ€ 1,437 Employees Infected via Fake Zoom Updates â Spyware Deployed Under Cover of âProductivityâ\n\n> 1,437 Windows users got âupdatedâ⊠by their boss. đ€ Clicking a fake Zoom waiting room installed spyware that logs keystrokes, screenshots, and your last DM to your ex. All in 30 seconds. Microsoft Defender didnât notice until it was too late. Your companyâs âproductivity toolâ? Itâs now a backdoor. â Whoâs really monitoring whom? đ”ïžââïž\n\n**1,437 U.S. Windows boxes** got a surprise Zoom/Google Meet facelift last month. Click the âUpdate Availableâ banner in the fake waiting room andâboomâlegit-looking MSI silently drops Teramind-flavored stalkerware, complete with keystroke Hoover, screen recorder, and two cockroach services (tsvchSt & pmon) that auto-respawn faster than your caffeine habit.\n\n### How this turkey trots\n\nPhish link â cloned waiting room â 5-second ânetwork hiccupâ â bogus update prompt â MSI installs bossware binary under `C:\\ProgramData\\{4CECâŠ}` â services phone home. Zero VT detections on day-0; Defender noticed only after Feb-25 telemetry sync.\n\n### Pain inventory\n\n * **Privacy** : every keystroke, clipboard paste, screenshot â full credential pantry raided\n * **Wallet** : incident-response hours, poss. GDPR/CCPA fines â budget hemoglobin\n * **Ops** : persistent services survive reboots â eternal game of whack-a-mole\n\n\n\n### Cheap-ass defenses that actually work\n\n * Block unsigned MSI via GPOâfree.\n * Kill unknown services (tsvchSt, pmon) with `sc delete`âfree.\n * Train users: real waiting rooms never beg for updatesâfree.\n * Restrict outbound 443 to approved domainsânearly free.\n\n\n\n### Timeline of (probable) misery\n\n * **Q2 2026** : auto-gen URLs on hacked CDNs â 3Ă volume, still <10% AV catch rate\n * **Q4 2026** : Chrome-PWA variant drops, harvests cookies too\n * **Mid-2027** : ransomware crews bundle same bossware as âinitial access liteââexpect double-extortion invoices\n\n\n\n**Bottom line** : if your next meeting invite wants a software update, it isnât ITâitâs a bored crook turning your laptop into a 24/7 reality show. Patch the humans first; the machines can wait.\n\n* * *\n\n## đ„ mquire: SQL-Powered Linux Forensics Slash Incident Response Time â U.S. Enterprises Now Facing Zero-Symbol Era\n\n> 30% faster Linux forensics? đ± mquire pulls rootkits, deleted files & SSH sessions from RAM⊠WITHOUT debug symbols. đ€Ż Volatility needs 3 hours & a symbol library. mquire? SQL queries. In minutes. đâđ Your cloud ops team is still using 2018 tools while hackers own your kernels. Whoâs paying for the delay? â Whatâs your memory dump missing right now?\n\nTrail of Bits just gift-wrapped **mquire** , a Linux memory autopsy scalpel that carves open a dead box without begging for debug symbols. Translation: your incident-response crew can now SQL-query a corpse for hidden SSH backdoors, deleted âoopsâ files, and rootkit love-letters in **minutes, not hours** âprovided the kernel shipped after 2018 and the admin didnât neuter BTF. Cute.\n\n### How this zombie-whisperer actually works\n\n * **Rust engine** slurps BTF type gossip + kallsyms name-tags straight from the dump.\n * **Virtual tables** pop up like fake Excel sheets: processes, sockets, kernel modules, even that ârm -rfâ you thought vaporised.\n * One-liner: `SELECT * FROM network_connections WHERE remote_ip LIKE '198.51.100%';` boomâC2 IP on a silver platter.\n\n\n\n### Pain-scale impacts (because breach invoices need unit tests)\n\n * **Time hemorrhage** : old Volatility ritual = 45 % longer triage â analysts burn billable midnight oil.\n * **Evidence spoilage** : 30 % of page-cache ghost files evaporate after ~2 h uptimeâmquire grabs them before the kernel garbage-collects your smoking gun.\n * **Rootkit hide-and-seek** : dual task-list enumeration surfaces ~8 % more cloaked PIDs on averageâenough to turn a âcleanâ report into a rĂ©sumĂ©-generating event.\n\n\n\n### Gaps big enough to drive a compliance auditor through\n\n * **User-space blind spot** : BTF canât spell âC++ vtableââyou still need symbols for that plush malware written in fancy OOP.\n * **Kernel compile roulette** : disable BTF and mquire shrugs; youâre back to square-one symbol hunting.\n * **Table deficit** : no TPM, SELinux, cgroupsâso kiss your container escape forensics goodbye for now.\n\n\n\n### Timeline of delusion\n\n * **2026 Q2** : 10 % of Fortune 500 IR playbooks adopt â 15 GWh/year saved analyst juice (â 2.5 Mt less COâ from burnt midnight oil).\n * **2027** : script kiddies release anti-mquire RAM wipersâcat pisses back.\n * **2028** : kernel 6.4+ default; tool hits 35 % SOC market share, forcing commercial vendors to âinnovateâ by slapping SQL lipstick on their same old pigs.\n\n\n\n### Bottom line\n\nmquire doesnât magically fund your security team, patch your kernels, or stop the CFO from treating cyber-insurance like a warranty sticker. It simply turns post-breach Monday morning from a 6-hour symbol scavenger hunt into a 15-minute SQL slamâ**if** your infra isnât already BTF-lobotomised. Deploy it, script it, feed the output to your ELK stack, and maybeâ**maybe** âyouâll have enough evidence to convince the board that âinvisibleâ rootkits are, in fact, invoice-visible.\n\n* * *\n\n### In Other News\n\n * Coruna iOS exploit kit leverages hidden JavaScript and Lockdown Mode evasion to compromise 42,000+ devices, extracting crypto wallet data and enabling state-sponsored espionage\n * ExpressVPN launches Identity Defender app for U.S. users with up to $5M in identity theft insurance\n * TNSR 26.02 released with 30+ enhancements, DPDK 25.07 upgrade, and improved VPF HA state synchronization for enterprise packet processing\n\n",
"title": "Revoked Certificates Still Trusted: 2.4M Windows Systems Compromised â Microsoft Defender Fails Trust Chain â Enterprise Security Crisis",
"updatedAt": "2026-03-04T15:43:19.262Z"
}