• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
experts uncover darkcasino: new emerging apt threat exploiting winrar flaw

Experts Uncover DarkCasino: New Emerging APT Threat Exploiting WinRAR Flaw

You are here: Home / General Cyber Security News / Experts Uncover DarkCasino: New Emerging APT Threat Exploiting WinRAR Flaw
November 16, 2023

A hacking group that leveraged a not too long ago disclosed security flaw in the WinRAR software program as a zero-working day has now been categorized as an entirely new sophisticated persistent danger (APT).

Cybersecurity business NSFOCUS has explained DarkCasino as an “economically inspired” actor that initial arrived to mild in 2021.

“DarkCasino is an APT threat actor with strong complex and finding out ability, who is superior at integrating numerous well known APT attack technologies into its attack procedure,” the organization claimed in an evaluation.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“Attacks released by the APT team DarkCasino are very frequent, demonstrating a strong motivation to steal on the internet house.”

DarkCasino was most not too long ago connected to the zero-working day exploitation of CVE-2023-38831 (CVSS score: 7.8), a security flaw that can be weaponized to start malicious payloads.

Cybersecurity

In August 2023, Group-IB disclosed real-planet attacks weaponizing the vulnerability aimed at on the net trading message boards at the very least since April 2023 to deliver a closing payload named DarkMe, which is a Visual Fundamental trojan attributed to DarkCasino.

The malware is equipped to accumulate host information, just take screenshots, manipulate documents and Windows Registry, execute arbitrary instructions, and self-update by itself on the compromised host.

Though DarkCasino was beforehand labeled as a phishing marketing campaign orchestrated by the EvilNum team concentrating on European and Asian on-line gambling, cryptocurrency, and credit history platforms, NSFOCUS said its constant tracking of the adversary’s functions has authorized it rule out any likely connections with recognised risk actors.

WinRAR Flaw

The exact provenance of the risk actor is currently not known.

“In the early days, DarkCasino mostly operated in countries close to the Mediterranean and other Asian nations around the world applying on the net fiscal solutions,” it claimed.

“Far more recently, with the improve of phishing strategies, its attacks have achieved consumers of cryptocurrencies around the globe, even together with non-English-speaking Asian nations such as South Korea and Vietnam.”

Cybersecurity

Numerous risk actors have joined the CVE-2023-38831 exploitation bandwagon in recent months, which includes APT28, APT40, Dark Pink, Ghostwriter, Konni, and Sandworm.

Ghostwriter’s attack chains leveraging the shortcoming have been observed to pave the way for PicassoLoader, an intermediate malware that acts as a loader for other payloads.

“The WinRAR vulnerability CVE-2023-38831 brought by the APT group DarkCasino delivers uncertainties to the APT attack problem in the 2nd 50 percent of 2023,” NSFOCUS stated.

“Several APT teams have taken edge of the window period of time of this vulnerability to attack critical targets these kinds of as governments, hoping to bypass the defense technique of the targets and realize their needs.”

Identified this report interesting? Comply with us on Twitter  and LinkedIn to go through much more exceptional written content we submit.


Some components of this report are sourced from:
thehackernews.com

Previous Post: «cisa and fbi issue warning about rhysida ransomware double extortion CISA and FBI Issue Warning About Rhysida Ransomware Double Extortion Attacks
Next Post: Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups zero day flaw in zimbra email software exploited by four hacker»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.