Fun

News Feed - 2023-10-02 12:10:57

Brayden Lindrea5 hours agoCrypto firms beware: Lazarus’ new malware can now bypass detectionThe malware payload “LightlessCan” — used in fake job scams — is far more challenging to detect than its predecessor, warns cybersecurity researchers at ESET.2099 Total views25 Total sharesListen to article 0:00NewsJoin us on social networksNorth Korean hacking collective, the Lazarus Group, has been using a new type of “sophisticated” malware as part of its fake employment scams, which researchers warn is far more challenging to detect than its predecessor.


According to a Sept. 29 post from ESET’s senior malware researcher Peter Kálnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan.#ESET researchers unveiled their findings about an attack by the North Korea-linked #APT group #Lazarus that took aim at an aerospace company in Spain.

▶️ Find out more in a #WeekinSecurity video with @TonyAtESET. pic.twitter.com/M94J200VQx— ESET (@ESET) September 29, 2023


The Lazarus Group’s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage.


However, Kálnai says the new LightlessCan payload is a “significant advancement” compared with its predecessor, BlindingCan.


“LightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions,” Kálnai said.


“This approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,” he added.️‍♂️ Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest #WeLiveSecurity article. #ESET #ProgressProtected— ESET (@ESET) September 29, 2023


The new payload also uses what the researcher calls “execution guardrails,” ensuring that the payload can only be decrypted on the intended victim’s machine, thereby avoiding unintended decryption by security researchers.


Kálnai said one case involving the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.


Soon after, the hackers sent over the two simple coding challenges embedded with the malware. The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.


Cyberespionage was the primary motivation behind Lazarus Group’s attack on the Spain-based aerospace firm, he added.


Related:3 steps crypto investors can take to avoid hacks by the Lazarus Group


Since 2016, North Korean hackers have stolen an estimated $3.5 billion from cryptocurrency projects, according to a Sept. 14 report by blockchain forensics firm Chainalysis.


In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed “Operation Dream Job." 


Meanwhile, the United Nations has been trying to curtail North Korea’s cybercrime tactics at the international level, as it is understood North Korea is using the stolen funds to support its nuclear missile program.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Business# Security# Malware# Cybercrime# North Korea# Cybersecurity# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingDAOs need to learn from Burning Man for mainstream adoptionAI tech boom: Is the artificial intelligence market already saturated?

News Feed

Polymarket monthly volume hits $100M as presidential race heats up
Brayden Lindrea7 hours agoPolymarket monthly volume hits $100M as presidential race heats upOver $200 million worth of bets have been placed on who will win the United States presidential election in November.4913 Total
Eurosystem Seeks Providers of Prototype Payment Solutions for Digital Euro
Eurosystem Seeks Providers of Prototype Payment Solutions for Digital Euro Eurozone’s monetary authority, the Eurosystem, is looking to enlist financial companies willing to
As Lightning’s Economy Takes Shape, Devs Are Split on Proposed Fee Hike
Fees aren’t just a topic of discussion for bitcoin users anymore. As the tech matures and an economy develops, fee discussions are making their way into the lightning network too.
HBAR Breaks Above Massive Falling Wedge – Expert Sets $0.38 Target
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Short-Term Bitcoin Holders See 10% Profit – Potential Impact On Price?
Este artículo también está disponible en español. The Bitcoin market experienced a modest recovery over the past week following the 15.7% correction in the latter half of
21Shares files application for spot Solana ETF
Derek Andersen7 hours ago21Shares files application for spot Solana ETFThe proposed fund would be called the 21Shares Core Solana ETF and would not participate in staking SOL.775 Total views1 Total sharesListen to articl
South African Central Bank Warns Citizens Against Accepting Tainted Banknotes
South African Central Bank Warns Citizens Against Accepting Tainted Banknotes A week after more than 1,400 ATMs in South Africa were attacked during a looting sp
3 Ways Staking Will Upend the Economics of Ethereum
The Takeaway New analysis of the economic model behind ethereum 2.0 suggests validators can expect to earn 4.6–10.3 percent in annualized rewards at the start. The hardware cost for running ethereum 2.0 validator softw
Marcel Pechman6 hours agoBitcoin futures open interest at 2023 high while BTC trading volume at yearly low — What gives?BTC futures open interest is on the rise, but Bitcoin trading volume suggests that traders have sh
Itau Unibanco Mulls Offering Crypto Services, Opens Tokenization Unit in Brazil
Itau Unibanco Mulls Offering Crypto Services, Opens Tokenization Unit in Brazil Itaú Unibanco, one of the largest holding companies in Brazil, has announced it is considering
Simple Ledger Protocol Universe Is Thriving: Lottery, Mint, ATMs, Over 8,500 SLP Tokens Created
Simple Ledger Protocol Universe Is Thriving: Lottery, Mint, ATMs, Over 8,500 SLP Tokens CreatedIt’s been close to twelve months since we reported on the vast Simple Ledger Pro
Chinese Central Bank Governor: User Privacy and Financial Security Key Principles Guiding CBDC Design Process
Chinese Central Bank Governor: User Privacy and Financial Security Key Principles Guiding CBDC Design Process According to Yi Gang, governor of China’s central bank, the proc