• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
vietnamese hackers target u.k., u.s., and india with darkgate malware

Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware

You are here: Home / General Cyber Security News / Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware
October 20, 2023

Attacks leveraging the DarkGate commodity malware focusing on entities in the U.K., the U.S., and India have been linked to Vietnamese actors connected with the use of the notorious Ducktail stealer.

“The overlap of resources and strategies is incredibly probably owing to the consequences of a cybercrime marketplace,” WithSecure mentioned in a report released right now. “Danger actors are able to receive and use several various tools for the same reason, and all they have to do is appear up with targets, campaigns, and lures.”

Cybersecurity

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The advancement arrives amid an uptick in malware strategies employing DarkGate in latest months, primarily driven by its author’s determination to rent it out on a malware-as-a-company (MaaS) basis to other menace actors after employing it privately considering the fact that 2018.

It really is not just DarkGate and Ducktail, for the Vietnamese risk actor cluster liable for these strategies is leveraging similar or incredibly related lures, themes, targeting, and shipping techniques to also provide LOBSHOT and RedLine Stealer.

Attack chains distributing DarkGate are characterised by the use of AutoIt scripts retrieved via a Visible Fundamental Script despatched through phishing e-mail or messages on Skype or Microsoft Teams. The execution of the AutoIt script potential customers to the deployment of DarkGate.

In this scenario, having said that, the initial an infection vector was a LinkedIn message that redirected the target to a file hosted on Google Generate, a procedure normally utilised by Ducktail actors.

Cybersecurity

“Very very similar marketing campaign themes and lures have been utilised to produce Ducktail and DarkGate,” WithSecure mentioned, even though the function of the remaining-phase differs to terrific extent.

Whilst Ducktail capabilities as a stealer, DarkGate is a remote obtain trojan (RAT) with info-thieving abilities that also set up covert persistence on the compromised hosts for backdoor obtain.

“DarkGate has been all around for a prolonged time and is being utilised by lots of teams for diverse reasons, and not just this team or cluster in Vietnam,” security researcher Stephen Robinson, senior risk intelligence analyst at WithSecure, stated.

“The flipside of this is that actors can use several equipment for the identical campaign, which could obscure the legitimate extent of their activity from purely malware-primarily based examination.”

Discovered this report fascinating? Follow us on Twitter  and LinkedIn to go through far more unique written content we submit.


Some sections of this short article are sourced from:
thehackernews.com

Previous Post: «unleashing the power of the internet of things and cyber Unleashing the Power of the Internet of Things and Cyber Security
Next Post: Malvertisers Using Google Ads to Target Users Searching for Popular Software malvertisers using google ads to target users searching for popular»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.