Over View - Your Daily News Source
  • Home
  • News
    • Business
    • Politics
    • Science
  • Lifestyle
    • Food
    • Travel
    • Health
    • Fashion
  • Entertainment
    • Entertainment
    • Sports
  • Tech
No Result
View All Result
  • Home
  • News
    • Business
    • Politics
    • Science
  • Lifestyle
    • Food
    • Travel
    • Health
    • Fashion
  • Entertainment
    • Entertainment
    • Sports
  • Tech
No Result
View All Result
Over View - Your Daily News Source
No Result
View All Result
Home Tech

North Korean hackers return with updated version of this dangerous malware

November 16, 2022
in Tech
0
North Korean hackers return with updated version of this dangerous malware
  1. Home
  2. News
  3. Computing
An abstract image of padlocks overlaying a digital background.



(Image credit: Shutterstock)

Infamous North Korean hacking collective Lazarus Group is using an updated version of its DTrack backdoor to target firms in Europe, and Latin America. The group is out for money, Kaspersky researchers are saying, as the campaign is purely driven by profit. 

BleepingComputer (opens in new tab) has reported that the threat actors are using the updated DTrack to target companies in Germany, Brazil, India, Italy, Mexico, Switzerland, Saudi Arabia, Turkey, and the United States. 

The firms under fire include government research centers, policy institutes, chemical manufacturers, IT service providers, telecommunication providers, utility service providers, and education firms.

Modular backdoor

DTrack is described as a modular backdoor. It can log keystrokes, take screenshots, exfiltrate browser history, view running processes, and obtain network connection information. 

It can also run different commands on the target endpoint, download additional malware, and exfiltrate data. 

Post-update, DTrack now uses API hashing to load libraries and functions, instead of obfuscated strings and that it now uses just three command and control (C2) servers, compared to the previous six.

Some of the C2 servers Kaspersky uncovered as being used by the backdoor are “pinkgoat[.]com”, “purewatertokyo[.]com”, “purplebear[.]com”, and “salmonrabbit[.]com.”

It also found that DTrack distributes malware labelled with file names usually associated with legitimate executables.

In one case, it was said, the backdoor was hiding behind “NvContainer.exe”, an executable file usually distributed by NVIDIA. The group would use stolen credentials to log into target networks, or would exploit internet-exposed servers to install the malware.

  • These are the best internet security suites right now

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More

Previous Post

Telehealth Sites Put Addiction Patient Data at Risk

Next Post

Xbox Game Pass Ultimate is giving you a great reason to finally try Apple TV Plus

Next Post
Xbox Game Pass Ultimate is giving you a great reason to finally try Apple TV Plus

Xbox Game Pass Ultimate is giving you a great reason to finally try Apple TV Plus

Stay Connected

  • Trending
  • Comments
  • Latest
Price of Micah Parsons’s Haircut Just Went Up Tremendously

Price of Micah Parsons’s Haircut Just Went Up Tremendously

November 23, 2022
Tesla’s shares hit a two-year low as investors worry about Elon Musk’s focus on Twitter and a growing list of bad news

Tesla’s shares hit a two-year low as investors worry about Elon Musk’s focus on Twitter and a growing list of bad news

November 25, 2022
German home prices to fall 3.5% next year as buyers feel the pinch

German home prices to fall 3.5% next year as buyers feel the pinch

November 23, 2022
Black Friday Apple deals live: record-low prices on Airpods, iPads, Apple Watch

Black Friday Apple deals live: record-low prices on Airpods, iPads, Apple Watch

November 25, 2022
The best genderless skin care products

The best genderless skin care products

The U.S. Will Cut Emissions In An Effort To Avoid ‘Climate Hell,’ Biden Says

The U.S. Will Cut Emissions In An Effort To Avoid ‘Climate Hell,’ Biden Says

Truly Heroic: Meet The Inspirational Owner Of Norway’s Esports Powerhouse

Truly Heroic: Meet The Inspirational Owner Of Norway’s Esports Powerhouse

The Untold Story Behind Emax, The Cryptocurrency Kim Kardashian Got Busted For Hyping

The Untold Story Behind Emax, The Cryptocurrency Kim Kardashian Got Busted For Hyping

Xterra Colombia joins 2024 Xterra Americas Tour

Xterra Colombia joins 2024 Xterra Americas Tour

June 3, 2023
Start-to-Finish and free of charge livestream for Challenge Roth

Start-to-Finish and free of charge livestream for Challenge Roth

June 3, 2023
‘Fire is still there’ for Gwen Jorgensen despite her ‘worst swim ever’

‘Fire is still there’ for Gwen Jorgensen despite her ‘worst swim ever’

June 3, 2023
‘Not worse-case scenario, but not best either’ – Ruth Astle injury update

‘Not worse-case scenario, but not best either’ – Ruth Astle injury update

June 3, 2023

Recent News

Xterra Colombia joins 2024 Xterra Americas Tour

Xterra Colombia joins 2024 Xterra Americas Tour

June 3, 2023
Start-to-Finish and free of charge livestream for Challenge Roth

Start-to-Finish and free of charge livestream for Challenge Roth

June 3, 2023
‘Fire is still there’ for Gwen Jorgensen despite her ‘worst swim ever’

‘Fire is still there’ for Gwen Jorgensen despite her ‘worst swim ever’

June 3, 2023
‘Not worse-case scenario, but not best either’ – Ruth Astle injury update

‘Not worse-case scenario, but not best either’ – Ruth Astle injury update

June 3, 2023

No Result
View All Result
  • Entertainment
    • Entertainment
    • Sports
  • Lifestyle
    • Fashion
    • Health
    • Travel
    • Food
  • News
    • Business
    • Politics
    • Science
  • Tech