Fun

News Feed - 2023-10-02 12:10:57

Brayden Lindrea5 hours agoCrypto firms beware: Lazarus’ new malware can now bypass detectionThe malware payload “LightlessCan” — used in fake job scams — is far more challenging to detect than its predecessor, warns cybersecurity researchers at ESET.2099 Total views25 Total sharesListen to article 0:00NewsJoin us on social networksNorth Korean hacking collective, the Lazarus Group, has been using a new type of “sophisticated” malware as part of its fake employment scams, which researchers warn is far more challenging to detect than its predecessor.


According to a Sept. 29 post from ESET’s senior malware researcher Peter Kálnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan.#ESET researchers unveiled their findings about an attack by the North Korea-linked #APT group #Lazarus that took aim at an aerospace company in Spain.

▶️ Find out more in a #WeekinSecurity video with @TonyAtESET. pic.twitter.com/M94J200VQx— ESET (@ESET) September 29, 2023


The Lazarus Group’s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage.


However, Kálnai says the new LightlessCan payload is a “significant advancement” compared with its predecessor, BlindingCan.


“LightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions,” Kálnai said.


“This approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,” he added.️‍♂️ Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest #WeLiveSecurity article. #ESET #ProgressProtected— ESET (@ESET) September 29, 2023


The new payload also uses what the researcher calls “execution guardrails,” ensuring that the payload can only be decrypted on the intended victim’s machine, thereby avoiding unintended decryption by security researchers.


Kálnai said one case involving the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.


Soon after, the hackers sent over the two simple coding challenges embedded with the malware. The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.


Cyberespionage was the primary motivation behind Lazarus Group’s attack on the Spain-based aerospace firm, he added.


Related:3 steps crypto investors can take to avoid hacks by the Lazarus Group


Since 2016, North Korean hackers have stolen an estimated $3.5 billion from cryptocurrency projects, according to a Sept. 14 report by blockchain forensics firm Chainalysis.


In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed “Operation Dream Job." 


Meanwhile, the United Nations has been trying to curtail North Korea’s cybercrime tactics at the international level, as it is understood North Korea is using the stolen funds to support its nuclear missile program.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Business# Security# Malware# Cybercrime# North Korea# Cybersecurity# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingDAOs need to learn from Burning Man for mainstream adoptionAI tech boom: Is the artificial intelligence market already saturated?

News Feed

TRUMP Coin Spikes 17% As Arthur Hayes Says It Could Outperform Bitcoin
Este artículo también está disponible en español. The former BitMEX CEO, Arthur Hayes, is making a bold prediction for the TRUMP meme coin: it will outperform Bitcoin if
Report: Over 30,000 Nigerians to Learn About Blockchain From Government Agency
Report: Over 30,000 Nigerians to Learn About Blockchain From Government Agency Nigeria’s National Information Technology Development Agency recently said it has launched a b
Bitcoin of America Is Working to Solve the Gender Problem in the Crypto Industry
Bitcoin of America Is Working to Solve the Gender Problem in the Crypto Industry sponsored The leading virtual currency exchange, Bitcoin of America, announced its return to BTC 202
Biggest Movers: DOGE, XRP Rebound Following Recent Declines
Biggest Movers: DOGE, XRP Rebound Following Recent Declines Following two days of declines, dogecoin rebounded earlier in today’s session, moving away from a key level of su
World Gold Council Exec Believes Blockchain Technology Will Bolster Trust in the Gold Industry
World Gold Council Exec Believes Blockchain Technology Will Bolster Trust in the Gold Industry The World Gold Council’s (WGC) head of global sales and regional CEO, Joe Cava
Microstrategy Buys 301 Bitcoin, Public Company Now Holds 130,000 BTC
Microstrategy Buys 301 Bitcoin, Public Company Now Holds 130,000 BTC According to Microstrategy’s executive chairman Michael Saylor, his company has recently purchased 301 b
Bitcoin price hits $61K, but investors still prefer stocks and bonds right now
Marcel Pechman2 hours agoBitcoin price hits $61K, but investors still prefer stocks and bonds right nowInvestors balance risk as Bitcoin futures dip, reflecting uncertainty before the Federal Reserve"s September meeting.
Spanish Securities Regulator Orders Binance to Stop Offering Cryptocurrency Derivatives
Spanish Securities Regulator Orders Binance to Stop Offering Cryptocurrency Derivatives The Spanish securities regulator, the CNMV, has ordered Binance to stop offering cryptocurre
Wolfgang Rückerl10 hours agoWeb3 mass adoption: How Web3 can onboard the next billion usersBy conquering these hurdles, we can help kickstart mass adoption while still maintaining the original decentralized spirit of We
Solana’s $110 Test: Bullish Reversal Or Whale-Driven Fade?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Bitcoin May See Brief Bounce After Defending Key Price Support
View Bitcoin is defending the key 200-day moving average support for the third consecutive day and may see a minor bounce to $8,700. A corrective bounce, if any, will likely be short-lived, as the daily and weekly chart
Déjà Boom—Arthur Hayes Says Bitcoin’s 2022 Rally Setup Is Back
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu