• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
a new apt hacker group spying on hotels and governments

A New APT Hacker Group Spying On Hotels and Governments Worldwide

You are here: Home / General Cyber Security News / A New APT Hacker Group Spying On Hotels and Governments Worldwide
September 25, 2021

A new advanced persistent menace (APT) has been powering a string of attacks against motels across the environment, alongside with governments, worldwide companies, engineering organizations, and legislation companies.

Slovak cybersecurity company ESET codenamed the cyber espionage team FamousSparrow, which it mentioned has been active given that at the very least August 2019, with victims located across Africa, Asia, Europe, the Middle East, and the Americas, spanning numerous international locations this kind of as Burkina Faso, Taiwan, France, Lithuania, the U.K., Israel, Saudi Arabia, Brazil, Canada, and Guatemala.

Attacks mounted by the team entail exploiting regarded vulnerabilities in server apps these as SharePoint and Oracle Opera, in addition to the ProxyLogon remote code execution vulnerability in Microsoft Exchange Server that came to light-weight in March 2021, making it the latest danger actor to have experienced accessibility to the exploit before details of the flaw became general public.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


According to ESET, intrusion exploiting the flaws commenced on March 3, ensuing in the deployment of a number of malicious artifacts, which include two bespoke variations of Mimikatz credential stealer, a NetBIOS scanner named Nbtscan, and a loader for a tailor made implant dubbed SparrowDoor.

Installed by leveraging a strategy called DLL research purchase hijacking, SparrowDoor functions as a utility to burrow into new corners of the target’s internal network that hackers also gained access to execute arbitrary commands as well as amass and exfiltrate sensitive information and facts to a distant command-and-management (C2) server less than their management.

Prevent Data Breaches

When ESET didn’t attribute the FamousSparrow team to a specific country, it did locate similarities in between its methods and individuals of SparklingGoblin, an offshoot of the China-linked Winnti Group, and DRBControl, which also overlaps with malware earlier determined with Winnti and Emissary Panda campaigns.

“This is yet another reminder that it is critical to patch internet-dealing with apps rapidly, or, if speedy patching is not possible, to not expose them to the internet at all,” ESET researchers Tahseen Bin Taj and Matthieu Faou mentioned.

Observed this report exciting? Follow THN on Fb, Twitter  and LinkedIn to read a lot more exceptional content material we write-up.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords
Next Post: SonicWall Issues Patches for a New Critical Flaw in SMA 100 Series Devices sonicwall issues patches for a new critical flaw in sma»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.