AIネットワーク社会推進会議(第30回)・AIガバナンス検討会(第26回)合同会議
「辺地共聴施設の高度化支援事業」に係る提案の公募
第50回衆議院議員総選挙における総務大臣表彰
令和6年度優良少年消防クラブ・指導者表彰(フレンドシップ)
地域社会DXにおける推進体制構築支援の支援地域候補の選定結果及び伴走支援事業者の公募・公募説明会の開催
接続料の算定等に関する研究会(第93回)の開催について
特性試験の試験方法を定める件の一部を改正する告示案に係る意見募集
村上総務大臣閣議後記者会見の概要
岩手県大船渡市の林野火災に関する被害状況等について(第15報)
【お知らせ】日本ジャーナリスト会議(JCJ)2025年度定期総会開催。3月29日(土)13時からオンラインで開催=JCJ事務局<br />
根津公子の都教委傍聴記 : 子どもの数は減っているのに「知的障害」児が増加すると都教委
ひょうたん島研究会:「千葉県知事選」雑感
「闘っている同世代がいることを知って衝撃だった」〜311子ども甲状腺がん裁判第13回口頭弁論
児玉繁信 : トランプ―ゼレンスキー会談をどのようにとらえるべきか?
食品安全委員会(第975回)の開催について【3月11日開催】
肥料・飼料等専門調査会(第207回)の開催について(非公開)【3月14日開催】
農薬第一専門調査会(第35回)の開催について(非公開)【3月14日開催】
Simple Phish Bait: EFF Is Not Investigating Your Albion Online Forum Account
We recently learned that users of the Albion Online gaming forum have received direct messages purporting to be from us. That message, which leverages the fear of an account ban, is a phishing attempt.
If you’re an Albion Online forum user and receive a message that claims to be from “the EFF team,” don’t click the link, and be sure to use the in-forum reporting tool to report the message and the user who sent it to the moderators.
A screenshot of the message shared by a user of the forums.
The message itself has some of the usual hallmarks of a phishing attempt, including tactics like creating a sense of fear that your account may be suspended, leveraging the name of a reputable group, and further raising your heart rate with claims that the message needs a quick response. The goal appears to be to get users to download a PDF file designed to deliver malware. That PDF even uses our branding and typefaces (mostly) correctly.
A full walk through of this malware and what it does was discovered by the Hunt team. The PDF is a trojan, or malware disguised as a non malicious file or program, that has an embedded script that calls out to an attacker server. The attacker server then sends a “stage 2” payload that installs itself onto the user’s device. The attack structure used was discovered to be the Pyramid C2 framework. In this case, it is a Windows operating system intended malware. There’s a variety of actions it takes, like writing and modifying files to the victim’s physical drive. But the most worrisome discovery is that it appears to connect the user’s device to a malicious botnet and has potential access to the “VaultSvc” service. This service securely stores user credentials, such as usernames and passwords
File-based IoCs:
act-7wbq8j3peso0qc1.pages[.]dev/819768.pdf
Hash: 4674dec0a36530544d79aa9815f2ce6545781466ac21ae3563e77755307e0020
This incident is a good reminder that often, the best ways to avoid malware and phishing attempts are the same: avoid clicking strange links in unsolicited emails, keep your computer’s software updated, and always scrutinize messages claiming to come from computer support or fraud detection. If a message seems suspect, try to verify its authenticity through other channels—in this case, poking around on the forum and asking other users before clicking on anything. If you ever absolutely must open a file, do so in an online document reader, like Google Drive, or try sending the link through a tool like VirusTotal, but try to avoid opening suspicious files whenever possible.
For more information to help protect yourself, check out our guides for protecting yourself from malware and avoiding phishing attacks.