• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
guyana governmental entity hit by dinodasrat in cyber espionage attack

Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack

You are here: Home / General Cyber Security News / Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack
October 5, 2023

A governmental entity in Guyana has been qualified as element of a cyber espionage marketing campaign dubbed Operation Jacana.

The action, which was detected by ESET in February 2023, entailed a spear-phishing attack that led to the deployment of a hitherto undocumented implant composed in C++ called DinodasRAT.

The Slovak cybersecurity company reported it could backlink the intrusion to a recognized danger actor or team, but attributed with medium self esteem to a China-nexus adversary owing to the use of PlugX (aka Korplug), a remote entry trojan prevalent to Chinese hacking crews.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“This campaign was qualified, as the risk actors crafted their e-mails particularly to entice their selected target business,” ESET mentioned in a report shared with The Hacker News.

“Soon after efficiently compromising an original but restricted established of devices with DinodasRAT, the operators proceeded to shift inside of and breach the target’s inner network, in which they again deployed this backdoor.”

The infection sequence commenced with a phishing email made up of a booby-trapped website link with issue traces referencing an alleged news report about a Guyanese fugitive in Vietnam.

Ought to a recipient simply click on the website link, a ZIP archive file is downloaded from the area fta.moit.gov[.]vn, indicating a compromise of a Vietnamese governmental web-site to host the payload.

Embedded inside of the ZIP archive is an executable that launches the DinodasRAT malware to acquire sensitive data from a victim’s personal computer.

DinodasRAT, moreover encrypting the information it sends to the command-and-command (C2) server working with the Tiny Encryption Algorithm (TEA), will come with capabilities to exfiltrate technique metadata, documents, manipulate Windows registry keys, and execute instructions.

Cybersecurity

Also deployed are tools for lateral motion, Korplug, and the SoftEther VPN consumer, the latter of which has been place to use by a different China-affiliated cluster tracked by Microsoft as Flax Hurricane.

“The attackers utilised a mixture of earlier unknown applications, these types of as DinodasRAT, and far more classic backdoors this kind of as Korplug,” ESET researcher Fernando Tavella explained.

“Dependent on the spear-phishing emails employed to gain original accessibility to the victim’s network, the operators are keeping track of the geopolitical routines of their victims to maximize the chance of their operation’s results.”

Identified this write-up fascinating? Adhere to us on Twitter  and LinkedIn to examine much more unique written content we post.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «golddigger android trojan targets banking apps in asia pacific countries GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries
Next Post: Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities analysis and config extraction of lu0bot, a node.js malware with»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.