Attacks by North Korean state-backed attackers have not only resulted in the theft of $235 million from major Indian cryptocurrency exchange WazirX in July but also led to losses of $308 million for DMM Bitcoin, $100 million for Radiant Capital and Upbit combined, and $16.13 million for Rain Management.
Impacted websites, whose initial means of compromise remains uncertain, had a script retrieved from the wp3[.]xyz domain enabling the establishment of a deceptive admin account before installing an information-stealing plugin targeting admin credentials, logs, and other sensitive details, a report from c/side, a webscript security firm, revealed.
Acquisition of warrants in August enabled the U.S. Department of Justice and FBI to remotely target PlugX-impacted systems with a self-destruct command that not only removed malware files and registry keys but also established a temporary script to remove the PlugX app following the cessation of its operations.
The last ShmooCon hacker conference showcased new ways to turn the tables on attackers and new ways to entertain your kids with computer-controlled light wands.
UAC-0063 leveraged trojanized legitimate documents from Kazakhstan's Ministry of Foreign Affairs tackling the country's diplomatic cooperation with other nations between 2021 and 2024 to facilitate the distribution of the Hatvibe and Cherryspy payloads, a report from Sekoia revealed.
Attacks by RedDelta commence with spear-phishing emails using Mongolian flood protection, Taiwanese presidential candidate Terry Gou, and an Association of Southeast Asian Nations meeting as lures that contain malicious MSI, MSC, and LNK files to facilitate PlugX malware compromise, according to an analysis from Recorded Future's Insikt Group.
Executing the bogus exploit — which is based on the legitimate PoC created by SafeBreach Labs but contains the UPX-packed poc.exe file — launches a PowerShell script in the targeted system's %Temp% folder that establishes a script-executing scheduled job to facilitate the eventual retrieval of the infostealing payload, according to a Trend Micro analysis.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.