Fun

News Feed - 2023-10-02 12:10:57

Brayden Lindrea5 hours agoCrypto firms beware: Lazarus’ new malware can now bypass detectionThe malware payload “LightlessCan” — used in fake job scams — is far more challenging to detect than its predecessor, warns cybersecurity researchers at ESET.2099 Total views25 Total sharesListen to article 0:00NewsJoin us on social networksNorth Korean hacking collective, the Lazarus Group, has been using a new type of “sophisticated” malware as part of its fake employment scams, which researchers warn is far more challenging to detect than its predecessor.


According to a Sept. 29 post from ESET’s senior malware researcher Peter Kálnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan.#ESET researchers unveiled their findings about an attack by the North Korea-linked #APT group #Lazarus that took aim at an aerospace company in Spain.

▶️ Find out more in a #WeekinSecurity video with @TonyAtESET. pic.twitter.com/M94J200VQx— ESET (@ESET) September 29, 2023


The Lazarus Group’s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage.


However, Kálnai says the new LightlessCan payload is a “significant advancement” compared with its predecessor, BlindingCan.


“LightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions,” Kálnai said.


“This approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,” he added.️‍♂️ Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest #WeLiveSecurity article. #ESET #ProgressProtected— ESET (@ESET) September 29, 2023


The new payload also uses what the researcher calls “execution guardrails,” ensuring that the payload can only be decrypted on the intended victim’s machine, thereby avoiding unintended decryption by security researchers.


Kálnai said one case involving the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.


Soon after, the hackers sent over the two simple coding challenges embedded with the malware. The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.


Cyberespionage was the primary motivation behind Lazarus Group’s attack on the Spain-based aerospace firm, he added.


Related:3 steps crypto investors can take to avoid hacks by the Lazarus Group


Since 2016, North Korean hackers have stolen an estimated $3.5 billion from cryptocurrency projects, according to a Sept. 14 report by blockchain forensics firm Chainalysis.


In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed “Operation Dream Job." 


Meanwhile, the United Nations has been trying to curtail North Korea’s cybercrime tactics at the international level, as it is understood North Korea is using the stolen funds to support its nuclear missile program.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Business# Security# Malware# Cybercrime# North Korea# Cybersecurity# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingDAOs need to learn from Burning Man for mainstream adoptionAI tech boom: Is the artificial intelligence market already saturated?

News Feed

Crypto users fooled by fake Elizabeth Warren letter proposing crypto tax
Turner Wright4 hours agoCrypto users fooled by fake Elizabeth Warren letter proposing crypto taxThe fake letter addressed to U.S. President Joe Biden suggested a 1% wealth tax on crypto holdings exceeding $500,000.3831 T
China’s Hebei Province Begins Crackdown on Crypto Mining and Trading, Reports Reveal
China’s Hebei Province Begins Crackdown on Crypto Mining and Trading, Reports Reveal Authorities in the Chinese province of Hebei have reportedly launched a campaign against cryp
Report Claims Harvard, Yale, and Brown University Endowments Have Been Discreetly Buying Bitcoin
Report Claims Harvard, Yale, and Brown University Endowments Have Been Discreetly Buying Bitcoin According to sources familiar with the matter, a number of Ivy L
Circle enables USDC transfers for BlackRock’s first tokenized fund
Helen Partz10 hours agoCircle enables USDC transfers for BlackRock’s first tokenized fundBlackRock USD Institutional Digital Liquidity Fund, the first tokenized fund launched by BlackRock, can now be transferred to Cir
Bitcoin Halving Approaches: Less Than 400 Days Until Block Reward Subsidy Is Cut in Half
Bitcoin Halving Approaches: Less Than 400 Days Until Block Reward Subsidy Is Cut in Half According to current statistics, the Bitcoin network is fewer than 56,000 blocks away and l
Dubai’s DIFC passes comprehensive digital asset law, new security law
Derek Andersen3 hours agoDubai’s DIFC passes comprehensive digital asset law, new security lawThe center claims it has created the world’s first comprehensive set of legal characteristics of digital assets as propert
Brayden Lindrea6 hours agoBrazil’s CBDC pilot contains code that can freeze or reduce funds, dev claimsPedro Magalhães, a blockchain developer who claims to have reverse-engineered Brazil’s pilot CBDC has found code
Analyst Expects US to Embrace Crypto With Proper Regulation in 2022 – Sees ‘Refreshed’ Bitcoin Bull Market
Analyst Expects US to Embrace Crypto With Proper Regulation in 2022 – Sees "Refreshed" Bitcoin Bull Market Analyst Mike McGlone with Bloomberg Intelligence has shared his outlook
McAfee Catches Heat After Welshing On Famous Bitcoin Bet
McAfee Catches Heat After Welshing On Famous Bitcoin Bet Many bold predictions about bitcoin’s price have been made over the years, but tech entrepreneur John McAfee’
Marathon Digital shares plunge 8% after Q2 revenue miss estimates
Ciaran Lyons7 hours agoMarathon Digital shares plunge 8% after Q2 revenue miss estimatesMarathon Digital has missed consensus estimates for the second quarter in a row, though its year-on-year performance has risen by 78
Wallstreetbets Founder Jaime Rogozinski and Wsbdapp Project Launch 15,000 Generative NFTs
Wallstreetbets Founder Jaime Rogozinski and Wsbdapp Project Launch 15,000 Generative NFTs On September 22, the team behind the Wallstreetbets defi application called Wsbdapp announ
Luna Foundation Buys 2,508 Bitcoin for $100 Million, Stash Is Only 495 BTC Away From Tesla’s Balance
Luna Foundation Buys 2,508 Bitcoin for $100 Million, Stash Is Only 495 BTC Away From Tesla"s Balance On April 13, Terra’s Luna Foundation Guard (LFG) acquired 2,508.94 bitco