Cyber Security News

Beware of Fake Outlook Troubleshooting Calls that Ends Up In Ransomware Deployment

A sophisticated cyber threat has emerged in recent weeks, targeting unsuspecting users with fake Outlook troubleshooting calls.

These calls, designed to appear legitimate, ultimately lead to the deployment of ransomware on the victim’s system.

The scam involves a malicious binary named CITFIX#37.exe, which is masquerading as a legitimate tool derived from the Sysinternals Desktops utility.

Cybersecurity researchers at Deutsche Telekom CERT noted that the scam begins with a call from individuals claiming to be from Microsoft or another reputable tech company.

They assert that there is an issue with the user’s Outlook account and offer to troubleshoot the problem.

Once the user grants access to their computer, the attackers download and install the CITFIX#37.exe malware.

This binary is signed with fake digital certificates, making it appear legitimate at first glance.

Scam Details

The CITFIX#37.exe malware has a SHA256 hash of 247e6a648bb22d35095ba02ef4af8cfe0a4cdfa25271117414ff2e3a21021886.

Despite being signed, it is not authenticated by Microsoft. Instead, it uses malicious code signers such as Cascade Tech-Trek Inc., AM MISBAH Tech Inc., and KouisMoa MegaByte Information Technology Co., Ltd.

Malicious code signers (Source – X)

The malware installation process show how the attackers use these fake certificates to deceive users into trusting the software.

Malware Installation (Source – X)

Once installed, the malware can lead to ransomware deployment, encrypting the user’s files and demanding payment in exchange for the decryption key.

To protect yourself from fake Outlook troubleshooting scams, always verify the caller’s identity, as legitimate companies like Microsoft will not contact you unexpectedly for issue resolution.

Be cautious about granting remote access to your computer unless you are absolutely certain of the caller’s authenticity.

Keeping your antivirus software up to date ensures better protection against emerging threats, while regularly backing up your data can help prevent loss in case of an attack.

By understanding how these attacks work and following best security practices, individuals can significantly reduce their risk of falling victim to ransomware and other malicious schemes.

Indicators of Compromise (IoCs)

  • File Name: CITFIX#37.exe
  • SHA256 Hash: 247e6a648bb22d35095ba02ef4af8cfe0a4cdfa25271117414ff2e3a21021886
  • Malicious Signers:
  • Cascade Tech-Trek Inc.
  • AM MISBAH Tech Inc.
  • KouisMoa MegaByte Information Technology Co., Ltd.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago