Threat actors from North Korea have been using the recently discovered security holes in ConnectWise ScreenConnect to spread a brand-new piece of malware known as TODDLERSHARK.
A research published by Kroll with The Hacker News claims that TODDLERSHARK shares similarities with well-known Kimsuky malware, including BabyShark and ReconShark.
The vulnerability in the ScreenConnect application’s setup wizard allowed the threat actor to take control of the victim workstation, according to security researchers Dave Truman, George Glass, and Keith Wojcieszek.
Then, using their newly acquired “hands on keyboard” access, they used cmd.exe to run mshta.exe, which contained a URL to the malware built on Visual Basic (VB) read more Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
