Fun

News Feed - 2023-10-02 12:10:57

Brayden Lindrea5 hours agoCrypto firms beware: Lazarus’ new malware can now bypass detectionThe malware payload “LightlessCan” — used in fake job scams — is far more challenging to detect than its predecessor, warns cybersecurity researchers at ESET.2099 Total views25 Total sharesListen to article 0:00NewsJoin us on social networksNorth Korean hacking collective, the Lazarus Group, has been using a new type of “sophisticated” malware as part of its fake employment scams, which researchers warn is far more challenging to detect than its predecessor.


According to a Sept. 29 post from ESET’s senior malware researcher Peter Kálnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan.#ESET researchers unveiled their findings about an attack by the North Korea-linked #APT group #Lazarus that took aim at an aerospace company in Spain.

▶️ Find out more in a #WeekinSecurity video with @TonyAtESET. pic.twitter.com/M94J200VQx— ESET (@ESET) September 29, 2023


The Lazarus Group’s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage.


However, Kálnai says the new LightlessCan payload is a “significant advancement” compared with its predecessor, BlindingCan.


“LightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions,” Kálnai said.


“This approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,” he added.️‍♂️ Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest #WeLiveSecurity article. #ESET #ProgressProtected— ESET (@ESET) September 29, 2023


The new payload also uses what the researcher calls “execution guardrails,” ensuring that the payload can only be decrypted on the intended victim’s machine, thereby avoiding unintended decryption by security researchers.


Kálnai said one case involving the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.


Soon after, the hackers sent over the two simple coding challenges embedded with the malware. The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.


Cyberespionage was the primary motivation behind Lazarus Group’s attack on the Spain-based aerospace firm, he added.


Related:3 steps crypto investors can take to avoid hacks by the Lazarus Group


Since 2016, North Korean hackers have stolen an estimated $3.5 billion from cryptocurrency projects, according to a Sept. 14 report by blockchain forensics firm Chainalysis.


In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed “Operation Dream Job." 


Meanwhile, the United Nations has been trying to curtail North Korea’s cybercrime tactics at the international level, as it is understood North Korea is using the stolen funds to support its nuclear missile program.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Business# Security# Malware# Cybercrime# North Korea# Cybersecurity# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingDAOs need to learn from Burning Man for mainstream adoptionAI tech boom: Is the artificial intelligence market already saturated?

News Feed

Call of Duty Mobile Includes a 100-Player Battle Royale Mode
Call of Duty: Mobile is set to launch on Android and iOS devices worldwide on Oct. 1, Activision announced late yesterday. The publisher is the latest to take the reputational weigh
The Moss Piglet Dilemma: Paypal Bans Payments to Merchants Using the Word ‘Tardigrade’
The Moss Piglet Dilemma: Paypal Bans Payments to Merchants Using the Word ‘Tardigrade’The popular payment provider Paypal has been known for cutting off a number of merchants an
Former US solicitor general claims regulators want to ‘debank’ crypto
Turner Wright2 hours agoFormer US solicitor general claims regulators want to ‘debank’ cryptoSeveral parties have filed amicus briefs with the appellate court in support of Custodia Bank receiving approval for a mast
LBank Exchange Will List ADENE (ADEN) on January 27, 2022
LBank Exchange Will List ADENE (ADEN) on January 27, 2022 press release PRESS RELEASE. INTERNET CITY, DUBAI, Jan. 25 2022 – LBank Exchange, a global digital asset trading pla
BlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup Connect
Helen Partz13 hours agoBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup ConnectBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator are set to host Startup Con
Derek Andersen3 hours agoGemini sues Genesis over GBTC shares used as Earn collateral, now worth $1.6BGenesis wants to use the shares’ initial value in claims and is not releasing additional collateral transferred by D
Bitcoin will crash to $50K, 10x Research warns
Josh O"Sullivan13 hours agoBitcoin will crash to $50K, 10x Research warnsAccording to 10x Research, Bitcoin’s potential drop below $50,000 is linked to dwindling buy flows and accelerating sell flows.15400 Total views1
Ethereum core devs launch ‘pump the gas’ effort to raise gas limit
Martin Young4 hours agoEthereum core devs launch ‘pump the gas’ effort to raise gas limitThe devs argue that raising the gas limit to 40 million will cut Ethereum’s layer-1 transaction fees by 15%–33%.2952 Total
Nestree Introduces NFT Aggregator Beta Service to Help Improve Usability and Overall Performance
Nestree Introduces NFT Aggregator Beta Service to Help Improve Usability and Overall Performance press release PRESS RELEASE. Nestree is a blockchain-based community messenger that
Jack Dorsey Says Square Is Considering Building a ‘Bitcoin Mining System Based on Custom Silicon’
Jack Dorsey Says Square Is Considering Building a "Bitcoin Mining System Based on Custom Silicon" Following the latest report from Cambridge University that shows a large percentag
Matt Damon Shares Story Behind His Crypto Commercial
Matt Damon Shares Story Behind His Crypto Commercial Famous Hollywood actor Matt Damon has revealed the story of how he became involved in creating a cryptocurrency commercial call
Virtual Assets Unleashes Retail Cash Reload Innovation for Purchasing Cryptocurrency
Virtual Assets Unleashes Retail Cash Reload Innovation for Purchasing CryptocurrencyInstantly add cash to your Crypto Dispensers account with Green Dot @ the Register