South Korean ERP Vendor’s Server Hacked to Spread Xctdoor Malware

The product update server of an unidentified South Korean enterprise resource planning (ERP) firm has been discovered to be infiltrated, allowing the delivery of Xctdoor, a Go-based backdoor.

The attack was detected in May 2024 by the AhnLab Security Intelligence Center (ASEC), which noted that the attack’s techniques were similar to those of Andariel, a sub-cluster of the notorious Lazarus Group, but did not link it to any known threat actor or group.

The resemblance is due to the North Korean opponent’s previous usage of the ERP solution in 2017 to infect software update programs with a malicious routine, thereby disseminating malware similar to Rifdoor, called HotCroissant.

The identical executable is claimed to have been altered in the most recent instance examined by ASEC in order to use the regsvr32.exe process to run a DLL file read more about South Korean ERP Vendor’s Server Hacked to Spread Xctdoor Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *