• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
north korean hackers weaponize fake research to deliver rokrat backdoor

North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor

You are here: Home / General Cyber Security News / North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor
January 22, 2024

Media companies and high-profile professionals in North Korean affairs have been at the acquiring conclusion of a new campaign orchestrated by a danger actor acknowledged as ScarCruft in December 2023.

“ScarCruft has been experimenting with new an infection chains, such as the use of a complex threat analysis report as a decoy, most likely focusing on consumers of threat intelligence like cybersecurity pros,” SentinelOne scientists Aleksandar Milenkoski and Tom Hegel explained in a report shared with The Hacker News.

The North Korea-joined adversary, also acknowledged by the identify APT37, InkySquid, RedEyes, Ricochet Chollima, and Ruby Sleet, is assessed to be section of the Ministry of Condition Security (MSS), putting it aside from Lazarus Team and Kimsuky, which are things within the Reconnaissance Basic Bureau (RGB).

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

The team is regarded for its concentrating on of governments and defectors, leveraging spear-phishing lures to produce RokRAT and other backdoors with the greatest aim of covert intelligence gathering in pursuit of North Korea’s strategic interests.

In August 2023, ScarCruft was linked to an attack on Russian missile engineering company NPO Mashinostroyeniya along with Lazarus Team in what has been deemed as a “very appealing strategic espionage mission” created to advantage its controversial missile software.

North Korean

Previously this week, North Korean condition media described that the state experienced carried out a test of its “underwater nuclear weapons procedure” in response to drills by the U.S., South Korea, and Japan, describing the workout routines as a risk to its nationwide security.

The latest attack chain observed by SentinelOne qualified an skilled in North Korean affairs by posing as a member of the North Korea Study Institute, urging the recipient to open up a ZIP archive file containing presentation elements.

Whilst seven of the nine information in the archive are benign, two of them are malicious Windows shortcut (LNK) files, mirroring a multi-stage infection sequence earlier disclosed by Check Position in May 2023 to distribute the RokRAT backdoor.

There is proof to suggest that some of the people who were focused all-around December 13, 2023, had been also formerly singled out a thirty day period prior on November 16, 2023.

SentinelOne claimed its investigation also uncovered malware – two LNK documents (“inteligence.lnk” and “news.lnk”) as properly as shellcode variants providing RokRAT – which is reported to be portion of the threat actor’s arranging and testing procedures.

Cybersecurity

While the previous shortcut file just opens the reputable Notepad application, the shellcode executed through information.lnk paves the way for the deployment of RokRAT, while this infection course of action is but to be observed in the wild, indicating its very likely use for long term strategies.

The progress is a indication that the nation-condition hacking crew is actively tweaking its modus operandi possible in an effort to circumvent detection in response to community disclosure about its methods and methods.

“ScarCruft remains dedicated to acquiring strategic intelligence and maybe intends to obtain insights into non-community cyber menace intelligence and protection strategies,” the researchers explained.

“This enables the adversary to attain a much better knowledge of how the global community perceives developments in North Korea, thus contributing to North Korea’s choice-producing processes.”

Uncovered this report interesting? Observe us on Twitter  and LinkedIn to study far more exceptional content material we article.


Some parts of this report are sourced from:
thehackernews.com

Previous Post: «mavengate attack could let hackers hijack java and android via MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries
Next Post: Apple Issues Patch for Critical Zero-Day in iPhones, Macs – Update Now apple issues patch for critical zero day in iphones, macs»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.