US Media, Retailers Targeted by New SparklingGoblin APT
#1
Information 
Quote:An emerging international cybergang is broadening its targets to include North American media firms, universities and one computer retailer. The advanced persistent threat (APT) group is new, according to researchers who dubbed it SparklingGoblin. Also new is a novel backdoor technique, called SideWalk, used by the APT to penetrate cybersecurity defenses.
 
SparklingGoblin, according to ESET researchers who named and discovered the crime group and backdoor, is an offshoot of another APT Winnti Group, first identified in 2013 by Kaspersky. ESET also said in a Tuesday report that the SideWalk backdoor is similar to one used by Winnti called Crosswalk.
 
Crosswalk and SideWalk, according the ESET, are both “modular backdoors used to exfiltrate system information and that can run shellcode sent by the C&C server.”

The group, which previously focused attacks on sectors in Macao, Hong Kong and Taiwan in 2020, is still active targeting victims via spearphishing campaigns that include a range of malicious payloads including PDFs (with LNK files), decoy Adobe Flash Players and booby-trapped JavaScript files. Researchers also theorize that initial compromises of victims may also include waterholes.

ESET said it first became aware of SparklingGoblin in May 2020 when tracking the Winnti APT. Researchers said that’s when they stumbled upon an unusual malware packer used to deliver malicious payloads to victims. An analysis of the malware inside the packer revealed “samples containing artifacts from both the Equation Group and Winnti Group,” researchers wrote in an analysis.

Read more: US Media, Retailers Targeted by New SparklingGoblin APT
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sysinternals Suite 07.05.2026
Sysinternals Suite...harlan4096 — 07:42
Tor Browser 15.0.13
Tor Browser 15.0.1...harlan4096 — 07:39
K-Lite Codec Pack 19.7.0 / 19.7.0 Update
Changes in 19.7.0:...harlan4096 — 07:39
Microsoft Edge 148.0.3967.54
Version 148.0.3967...harlan4096 — 07:37
AdGuard Browser Extension 5.4.1.3
AdGuard Browser Ex...harlan4096 — 07:35

[-]
Birthdays
Today's Birthdays
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>