Malware, Threat Intelligence

XenoRAT trojan launched in South Korean foreign embassy-aimed cyberespionage

Cyber security concept. Toy horse on a digital screen, symbolizes the attack of the Trojan virus. 3D illustration.

BleepingComputer reports that intrusions with the XenoRAT malware have been deployed against multiple European embassies across South Korea as part of a state-backed cyberespionage campaign that has been underway since March.

After initially targeting a Central European embassy in March, attackers believed to be North Korean state-backed threat group APT43, also known as Kimsuky, aimed to compromise a Western European embassy in May with an email involving the impersonation of a high-level EU delegation official before proceeding with U.S.-Korea military partnership lures in intrusions launched from June to July, according to an analysis from Trellix. Threat actors have sent malicious messages purporting to be official letters and meeting and event invitations containing password-protected ZIP files with a PDF-spoofing LNK file, which facilitates the delivery of XenoRAT. Aside from enabling keylogging, screenshot capturing, and webcam and microphone access, XenoRAT also allows file transfers and remote shell operations while ensuring persistence on targeted systems, said researchers, who also noted potential Chinese participation in the campaign owing to the timing of the attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds