As part of an ongoing campaign, threat actors continue to target Mexican organizations in order to distribute a modified version of SystemBC and AllaKore RAT.
The activity has been attributed by Arctic Wolf Labs to a financially motivated hacking group called Greedy Sponge. Targeting a broad range of industries, including retail, manufacturing, transportation, capital goods, entertainment, agriculture, the public sector, and commercial services, it is thought to have been operational since early 2021.
According to a cybersecurity firm’s analysis released last week, the AllaKore RAT payload has been significantly altered to allow threat actors to transmit specific banking credentials and one-of-a-kind authentication data back to their command-and-control (C2) server in order to perpetrate financial fraud.
The BlackBerry Research and Intelligence Team (now a part of Arctic Wolf) first reported the campaign’s details in January 2024. The attacks used drive-by compromises or phishing to spread booby-trapped ZIP files read more about Credential Theft and Remote Access Surge as AllaKore PureRAT and Hijack Loader Proliferate.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
