Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
As part of an ongoing campaign, threat actors continue to target Mexican organizations in order to distribute a modified version of SystemBC and AllaKore RAT.
The activity has been attributed by Arctic Wolf Labs to a financially motivated hacking group called Greedy Sponge. Targeting a broad range of industries, including retail, manufacturing, transportation, capital goods, entertainment, agriculture, the public sector, and commercial services, it is thought to have been operational since early 2021.
According to a cybersecurity firm's analysis released last week, the AllaKore RAT payload has been significantly altered to allow threat actors to transmit specific banking credentials and one-of-a-kind authentication data back to their command-and-control (C2) server in order to perpe...



