• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
vietnamese hackers target u.k., u.s., and india with darkgate malware

Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware

You are here: Home / General Cyber Security News / Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware
October 20, 2023

Attacks leveraging the DarkGate commodity malware focusing on entities in the U.K., the U.S., and India have been linked to Vietnamese actors connected with the use of the notorious Ducktail stealer.

“The overlap of resources and strategies is incredibly probably owing to the consequences of a cybercrime marketplace,” WithSecure mentioned in a report released right now. “Danger actors are able to receive and use several various tools for the same reason, and all they have to do is appear up with targets, campaigns, and lures.”

Cybersecurity

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The advancement arrives amid an uptick in malware strategies employing DarkGate in latest months, primarily driven by its author’s determination to rent it out on a malware-as-a-company (MaaS) basis to other menace actors after employing it privately considering the fact that 2018.

It really is not just DarkGate and Ducktail, for the Vietnamese risk actor cluster liable for these strategies is leveraging similar or incredibly related lures, themes, targeting, and shipping techniques to also provide LOBSHOT and RedLine Stealer.

Attack chains distributing DarkGate are characterised by the use of AutoIt scripts retrieved via a Visible Fundamental Script despatched through phishing e-mail or messages on Skype or Microsoft Teams. The execution of the AutoIt script potential customers to the deployment of DarkGate.

In this scenario, having said that, the initial an infection vector was a LinkedIn message that redirected the target to a file hosted on Google Generate, a procedure normally utilised by Ducktail actors.

Cybersecurity

“Very very similar marketing campaign themes and lures have been utilised to produce Ducktail and DarkGate,” WithSecure mentioned, even though the function of the remaining-phase differs to terrific extent.

Whilst Ducktail capabilities as a stealer, DarkGate is a remote obtain trojan (RAT) with info-thieving abilities that also set up covert persistence on the compromised hosts for backdoor obtain.

“DarkGate has been all around for a prolonged time and is being utilised by lots of teams for diverse reasons, and not just this team or cluster in Vietnam,” security researcher Stephen Robinson, senior risk intelligence analyst at WithSecure, stated.

“The flipside of this is that actors can use several equipment for the identical campaign, which could obscure the legitimate extent of their activity from purely malware-primarily based examination.”

Discovered this report fascinating? Follow us on Twitter  and LinkedIn to go through far more unique written content we submit.


Some sections of this short article are sourced from:
thehackernews.com

Previous Post: «unleashing the power of the internet of things and cyber Unleashing the Power of the Internet of Things and Cyber Security
Next Post: Malvertisers Using Google Ads to Target Users Searching for Popular Software malvertisers using google ads to target users searching for popular»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.