IObit Forum Members Targeted with Phishing Emails

NJCCIC Alert

Original Release Date: 1/21/2021

Summary

IObit, a Windows systems software development company known for optimization utilities and anti-malware programs, was compromised and exploited in order to deploy the DeroHE ransomware. IObit forum members were targeted via a phishing email that offered a free one-year license to the developer’s software. The enclosed link redirected recipients to a ZIP file hosted on an IObit forum page that contained digitally signed files from the legitimate IObit License Manager program; however, the IObitUnlocker.dll has been replaced with an unsigned malicious version. If the ZIP file is downloaded, DeroHE ransomware is installed. Researchers determined that the forums still appear to be compromised, with some 404-error and “not found” pages pushing adult content web advertisements. At the time of this writing, there is no known decryption tool for DeroHE ransomware.

Recommendations

The NJCCIC recommends users avoid clicking on links or opening attachments found in unsolicited emails or messages that convey a “too good to be true” offer. Additionally, users are urged to avoid IObit forum webpages until the compromise is contained. Further reporting may be found in the Bleeping Computer article and additional ransomware mitigation strategies can be found in NJCCIC’s Technical Guide.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.