Security News > 2020 > August > Mercenary Cyberspies Used Autodesk 3ds Max Exploits in Attacks

Mercenary Cyberspies Used Autodesk 3ds Max Exploits in Attacks
2020-08-26 13:46

A sophisticated hack-for-hire group specializing in industrial espionage exploited the Autodesk 3ds Max modeling and animation software in an attack aimed at a company involved in luxury real estate projects, cybersecurity firm Bitdefender reported on Wednesday.

According to Bitdefender researchers, the attackers collected data on the security systems and software used by the target before attempting to exfiltrate valuable information.

The company believes the attack may have started with a malicious 3ds Max plugin being sent to the victim.

The hackers leveraged MAXScript exploits - MaxScript is the scripting language in 3ds Max - to download and execute other files, collect information about the compromised systems, and deliver malware capable of capturing screenshots and stealing passwords and history data from a Chrome database.

A security advisory published earlier this month by Autodesk warns 3ds Max users of a MAXScript exploit named PhysXPluginMfx that can "Corrupt 3ds Max software's settings, run malicious code, and propagate to other MAX files on a Windows system if scene files containing the script are loaded into 3ds Max.".


News URL

http://feedproxy.google.com/~r/Securityweek/~3/6cfRxfaLIbo/mercenary-cyberspies-used-autodesk-3ds-max-exploits-attacks

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Autodesk 43 1 5 167 9 182
3DS 9 0 10 9 4 23