North Korea debuts new Electricfish malware in Hidden Cobra campaigns
#1
Quote:The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) have released a joint security advisory warning of a new strain of malware being used in North Korean cyberattacks.
 
Dubbed Electricfish, the malware was uncovered while the departments were tracking the activities of Hidden Cobra, a threat group believed to be state-sponsored and backed by the North Korean government.

Also known as the Lazarus group, Hidden Cobra has been connected to a variety of attacks against financial institutions, critical industrial players, and targets chosen for valuable intellectual property worldwide.
 
The description of Electricfish is based on one malicious 32-bit Windows executable. After reverse engineering the sample, the malware was found to contain a custom protocol which permits traffic to be funneled between source and destination IP addresses. Electricfish is, therefore, able to shift traffic through proxies by the attackers to reach outside of a victim network.

"The malware can be configured with a proxy server/port and proxy username and password," the advisory reads. "This feature allows connectivity to a system sitting inside of a proxy server, which allows the actor to bypass the compromised system's required authentication to reach outside of the network."

SOURCE: https://www.zdnet.com/article/north-kore...campaigns/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Mohammad.Poorya
Reply


Messages In This Thread
North Korea debuts new Electricfish malware in Hidden Cobra campaigns - by silversurfer - 10 May 19, 14:23

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.7 Added the ...Kool — 03:36
AnyDesk 8.0.3 for Linux
Version 8.0.3 for ...harlan4096 — 09:05
Google Chrome 149.0.7827.196/197
Google Chrome 149....harlan4096 — 09:04
System Restore Evolved: Windows 11 Point...
Imagine if a bad d...harlan4096 — 09:01
Avast 26.6.11050 & AVG 26.6.11050
Avast 26.6.11050 :...harlan4096 — 18:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig

[-]
Online Staff
There are no staff members currently online.

>