Tag: Malware Arsenal

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
News

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

Three separate pieces of cross-platform malware, PondRAT, ThemeForestRAT, and RemotePE, are distributed through a social engineering effort that has been linked to the Lazarus Group, a threat actor with ties to North Korea. An employee's system was compromised as a result of the 2024 attack, which was seen by NCC Group's Fox-IT and targeted a company in the decentralized finance (DeFi) industry. According to Yun Zheng Hu and Mick Koomen, the actor then carried out discovery from within the network by utilizing several RATs in conjunction with additional tools, such as to harvest credentials or proxy connections. The actor then switched to a more covert RAT, which probably indicated the attack's next phase. The threat actor starts the attack chain by posing as an actual employee o...
Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk
News

Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk

An "advanced and upgraded version" of a known malware called StealthVector is suspected of being used by the China-linked advanced persistent threat (APT) organization codenamed APT41 to deploy a backdoor known as MoonWalk that was previously unreported. Zscaler ThreatLabz, which identified the loader strain in April 2024, has named the new StealthVector variant—also known as DUSTPAN—DodgeBox. According to security researchers Yin Hong Chang and Sudeep Singh, DodgeBox is a loader that loads a new backdoor called MoonWalk. MoonWalk uses Google Drive for command-and-control (C2) communication and shares many of the evasion tactics used in DodgeBox. The name "APT41" refers to a well-known Chinese state-sponsored threat actor that has been operating actively since at least 2007 read ...