Fun

News Feed - 2023-10-02 12:10:57

Brayden Lindrea5 hours agoCrypto firms beware: Lazarus’ new malware can now bypass detectionThe malware payload “LightlessCan” — used in fake job scams — is far more challenging to detect than its predecessor, warns cybersecurity researchers at ESET.2099 Total views25 Total sharesListen to article 0:00NewsJoin us on social networksNorth Korean hacking collective, the Lazarus Group, has been using a new type of “sophisticated” malware as part of its fake employment scams, which researchers warn is far more challenging to detect than its predecessor.


According to a Sept. 29 post from ESET’s senior malware researcher Peter Kálnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan.#ESET researchers unveiled their findings about an attack by the North Korea-linked #APT group #Lazarus that took aim at an aerospace company in Spain.

▶️ Find out more in a #WeekinSecurity video with @TonyAtESET. pic.twitter.com/M94J200VQx— ESET (@ESET) September 29, 2023


The Lazarus Group’s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage.


However, Kálnai says the new LightlessCan payload is a “significant advancement” compared with its predecessor, BlindingCan.


“LightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions,” Kálnai said.


“This approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,” he added.️‍♂️ Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest #WeLiveSecurity article. #ESET #ProgressProtected— ESET (@ESET) September 29, 2023


The new payload also uses what the researcher calls “execution guardrails,” ensuring that the payload can only be decrypted on the intended victim’s machine, thereby avoiding unintended decryption by security researchers.


Kálnai said one case involving the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.


Soon after, the hackers sent over the two simple coding challenges embedded with the malware. The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.


Cyberespionage was the primary motivation behind Lazarus Group’s attack on the Spain-based aerospace firm, he added.


Related:3 steps crypto investors can take to avoid hacks by the Lazarus Group


Since 2016, North Korean hackers have stolen an estimated $3.5 billion from cryptocurrency projects, according to a Sept. 14 report by blockchain forensics firm Chainalysis.


In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed “Operation Dream Job." 


Meanwhile, the United Nations has been trying to curtail North Korea’s cybercrime tactics at the international level, as it is understood North Korea is using the stolen funds to support its nuclear missile program.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Business# Security# Malware# Cybercrime# North Korea# Cybersecurity# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingDAOs need to learn from Burning Man for mainstream adoptionAI tech boom: Is the artificial intelligence market already saturated?

News Feed

Bitcoin, Ethereum Technical Analysis: BTC Back Above $41,000 as Crypto Bulls Return
Bitcoin, Ethereum Technical Analysis: BTC Back Above $41,000 as Crypto Bulls Return Following recent losses, BTC rallied on Tuesday, as bulls appeared to have returned to cryptocur
LUNA 2.0 Token Loses 56% Since Last Week, Whistleblower Accuses Terraform Labs of Owning Shadow Wallets
LUNA 2.0 Token Loses 56% Since Last Week, Whistleblower Accuses Terraform Labs of Owning Shadow Wallets After climbing to $11.33 per unit seven days ago on May 30, Terra’s n
MTI Liquidators Reject Claim Peddled by Opponents, Insist the Entity ‘Was a Massive Fraudulent Scam’
MTI Liquidators Reject Claim Peddled by Opponents, Insist the Entity "Was a Massive Fraudulent Scam" Liquidators of Mirror Trading International (MTI) have attacked the claim that
Nigeria Protest Group Asks for Bitcoin Donations After Regulators Block Bank Account
Nigeria Protest Group Asks for Bitcoin Donations After Regulators Block Bank Account A Nigerian protest group called Feminist Coalition is asking well-wishers to
Ezra Reguerra15 hours agoEmurgo to invest and fill 21 areas ‘missing’ from Cardano — CEOEmurgo founder and CEO Ken Kodama told Cointelegraph that the company has identified 21 areas that Cardano is missing but are
Encryption Crackdown: Private Phone Network With 60,000 Users Dismantled by Law Enforcement
Encryption Crackdown: Private Phone Network With 60,000 Users Dismantled by Law EnforcementAn international law enforcement team has brought down an encrypted phone network with 60,
Bitcoin Price Outlook for October — Strong Dollar and Fed Rate Hike Gives Bears the Advantage
Bitcoin Price Outlook for October — Strong Dollar and Fed Rate Hike Gives Bears the Advantage Ten days into October, and ahead of this Wednesday’s U.S. inflation report, b
TSX-Listed Voyager Digital ‘Temporarily’ Suspends Trading, Deposits, and Withdrawals
TSX-Listed Voyager Digital "Temporarily" Suspends Trading, Deposits, and Withdrawals After the TSX-listed Voyager Digital revealed that it was owed $655 million from Three Arrows C
Bitcoin Mining Markets Heat Up: Ebang’s $41M Deficit, Bitmain’s Alleged 2020 Revenue
Bitcoin Mining Markets Heat Up: Ebang"s $41M Deficit, Bitmain"s Alleged 2020 RevenueThe Chinese ASIC mining rig manufacturer Bitmain reportedly pulled in $300 million in revenue dur
US Senator Booker: Cryptocurrency Can Bring Growth to American Economy if Properly Regulated
US Senator Booker: Cryptocurrency Can Bring Growth to American Economy if Properly Regulated U.S. Senator Cory Booker sees cryptocurrency as “an exciting innovation with the
Hong Kong Authorities Arrest Two Siblings Accused of Laundering $384 Million via Banks, Crypto Platform
Hong Kong Authorities Arrest Two Siblings Accused of Laundering $384 Million via Banks, Crypto Platform Authorities in Hong Kong have arrested two individuals accused of laundering
Bitcoin, Ethereum Technical Analysis: BTC Consolidates Above $28,000 on Monday
Bitcoin, Ethereum Technical Analysis: BTC Consolidates Above $28,000 on Monday Bitcoin started the week consolidating above the $28,000 level, as markets prepare for a big week of