Tag: AhnLab Security Intelligence Center (ASEC)

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
News

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Threat actors have used a newly fixed security vulnerability in Microsoft Windows Server Update Services (WSUS) to spread malware called ShadowPad. According to a report released last week by AhnLab Security Intelligence Center (ASEC), the attacker used PowerCat, an open-source PowerShell-based Netcat utility, to obtain a system shell (CMD), after which they downloaded and installed ShadowPad using certutil and curl. The attacker targeted Windows servers with WSUS enabled, exploiting CVE-2025-59287 for initial access. Chinese state-sponsored hacking groups employ ShadowPad, a modular backdoor that originally surfaced in 2015 and was dubbed a masterpiece of privately sold malware in Chinese espionage by SentinelOne in an August 2021 analysis. ShadowPad is thought to be a successor of...
New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer
News

New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer

Researchers studying cybersecurity are alerting people to a new operation that uses software cracks as a ruse to spread information thieves such as Lumma and ACR Stealer. ACR Stealer's distribution volume has increased since January 2025, according to the AhnLab Security Intelligence Center (ASEC). The use of a method known as dead drop resolver to extract the actual command-and-control (C2) server is a noteworthy feature of the stealer malware. This involves depending on trustworthy platforms such as Google Forms, Google Slides, Steam, and Telegraph on Telegram. According to ASEC, threat actors access the Base64-encoded C2 domain on a certain page read more about New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer. Get up to date on the latest cybersecu...
Cybercriminals Use Eclipse Jarsigner to Deploy XLoader Malware via ZIP Archives
News

Cybercriminals Use Eclipse Jarsigner to Deploy XLoader Malware via ZIP Archives

The DLL side-loading approach has been used by a malware campaign that uses a legal program connected to the Eclipse Foundation to distribute the XLoader malware. According to the AhnLab Security Intelligence Center (ASEC), the legitimate application utilized in the assault, jarsigner, is a file generated after the installation of the Eclipse Foundation's IDE package. It is a JAR (Java Archive) file signing utility. According to the South Korean cybersecurity company, the malware is sent as a compressed ZIP file that contains both the genuine executable and the DLLs that must be sideloaded in order for the malware to run read more about Cybercriminals Use Eclipse Jarsigner to Deploy XLoader Malware via ZIP Archives. Get up to date on the latest cybersecurity news and enhance your...