Tag: Nation-State Hackers

Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
News

Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack

A new malware known as Airstalk has been distributed by a suspected nation-state threat actor as part of a probable supply chain attack. The cluster is being tracked by Palo Alto Networks Unit 42 under the name CL-STA-1009, where "CL" stands for cluster and "STA" for state-backed incentive. According to an investigation by security experts Kristopher Russo and Chema Garcia, Airstalk abuses the AirWatch API for mobile device management (MDM), which is now known as Workspace ONE Unified Endpoint Management. It creates a secret command-and-control (C2) channel via the API, mostly to handle file uploads and custom device attributes using the AirWatch feature. Using a multi-threaded command-and-control (C2) communication protocol, the virus may take screenshots and harvest cookies, br...
ConnectWise breached in cyberattack linked to nation-state hackers
News

ConnectWise breached in cyberattack linked to nation-state hackers

ConnectWise, a provider of IT management software, claims that a suspected state-sponsored malware compromised its system and affected a small number of ScreenConnect users. In a brief advisory, ConnectWise disclosed that it had recently discovered suspicious activity in our environment that it believes was connected to a sophisticated nation-state actor. The activity only affected a very tiny percentage of ScreenConnect clients. We have started an inquiry with Mandiant, one of the top forensic specialists. We are working with law enforcement and have gotten in touch with all impacted customers. ConnectWise is a software firm established in Florida that offers cybersecurity, automation, RMM (remote monitoring and management), and IT management solutions to IT departments read mor...
Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain
News

Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain

APT41, also known as Brass Typhoon, Earth Baku, Wicked Panda, or Winnti, is a well-known Chinese nation-state actor that has been implicated in a highly skilled cyberattack against the gaming and gambling sector. The hackers surreptitiously obtained important data from the targeted organization over a minimum of six months, including but not restricted to network configurations, user passwords, and LSASS process secrets. Israeli cybersecurity startup Security Joes' co-founder and CEO, Ido Naor, stated in a statement provided to The Hacker News. The attackers kept updating their toolkit during the incursion in response to the security team's reaction. They modified their tactics and equipment to evade detection and preserve continuous access to the hacked network by watching the defe...
Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyber Attacks
News

Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyber Attacks

Large language models (LLMs) and artificial intelligence (AI) are being experimented with by nation-state entities connected to China, Iran, North Korea, and Russia to supplement their continuing cyberattack activities. The conclusions stem from a report that Microsoft and OpenAI jointly released, in which they claimed to have terminated the assets and accounts of five state-affiliated actors who had attempted to utilize its AI services for hostile cyber actions. According to a Microsoft report shared with The Hacker News, "Language support is a natural feature of LLMs and is attractive for threat actors with continuous focus on social engineering read more Microsoft OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyber Attacks. Get up to date on the latest cybersecurity n...
Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers
News

Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers

Numerous threat actors, including cybercrime gangs and nation-state teams, are using the services provided by an unknown Iranian company called Cloudzy. Halcyon stated in a new study released on Tuesday that "Cloudzy is incorporated in the United States, but it almost certainly operates out of Tehran, Iran - possibly in violation of U.S. sanctions - under the direction of someone going by the name Hassan Nozari." According to the Texas-based cybersecurity firm, the business serves as a command-and-control provider (C2P), giving attackers access to Remote Desktop Protocol (RDP) virtual private servers and other anonymous services that are used by ransomware affiliates and other cybercriminals to carry out their illegal activities read more Iranian Company Cloudzy Accused of Aiding Cy...