Menu

  • TV Channel
  • Latest
  • WSCA Sports Newsroom
  • Culture, Society & Lifestyle
    • How to & Style
    • Beauty & Hair Care
    • Healthcare
  • Business & Economy
    • Automotive Industry
    • Building & Construction Industry
    • Banking, Finance & Investment Industry
    • International Organizations
    • Companies
    • Furniture & Woodworking Industry
    • Insurance Industry
    • Food & Beverage Industry
    • Energy Industry
    • Electronics Industry
    • Consumer Goods
    • Conferences & Trade Fairs
    • Agriculture, Farming & Forestry Industry
  • Education
  • Entertainment
    • Media, Advertising & PR
    • Amusement, Gaming & Casino
      • Gaming
    • Book Publishing Industry
    • Comedy
    • Movie
    • Music
  • Law
    • Human Rights
  • Politics
    • Military Industry
  • Retail
    • Gifts, Games & Hobbies
    • Manufacturing
  • Science
    • Religion
    • IT Industry
    • Aviation & Aerospace Industry
    • Natural Disasters
    • Environment
  • Real Estate & Property Management
  • Emergency Services

Subscriptions

  • WSCA News

Recent News

  • Kiwisearches.com Launches Revolutionary People and Phone Search Service with Reverse Phone Lookup
  • NATO reacts to Putin's nuclear threat: 'Dangerous, irresponsible' – Hindustan Times
  • Experts list five most common merchandising mistakes in 2023

6 Sci-fi Gadgets in Movie We Wish Actually Existed

46 Views
July 8, 2022

The 10 best games to play on your new PlayStation 4

47 Views
July 7, 2022

Tesla’s Chinese factory just delivered its first cars

45 Views
July 6, 2022
WSCA News
  • Channel
  • WSCA
  • US News
  • Browse
    • US News
    • WSCA Sports
    • Movie
    • Music
    • Technology
    • Howto & Style
    • Entertainment
    • Gaming
  • Featuring
    • Youtube Video
    • Vimeo Video
    • Dailymotion Video
    • Self-hosted Video
    • User Profile
    • Playlists
    • User-created Playlist
    • Favorite Playlist (Private)
    • Watch Later Playlist (Private)
    • All JNews Features
  • Entertainment
    • Music
    • Movie
  • WSCA Sports
    • Tennis
    • Auto Racing
      • NASCAR
    • NCAA
    • Non MLB
    • MLB
    • NHL
    • English Premier League
    • NBA
  • WSCA
No Result
View All Result
  • Login
UPLOAD
WSCA News
No Result
View All Result
Home IT Industry
N Korea-linked group launches Dolphin backdoor, steals files of interest, communicates via Google Drive

N Korea-linked group launches Dolphin backdoor, steals files of interest, communicates via Google Drive

Share on FacebookShare on Twitter


DUBAI, UNITED ARAB EMIRATES, December 6, 2022 /EINPresswire.com/ — ESET researchers analyzed a previously unreported sophisticated backdoor used by the ScarCruft APT group. The backdoor, which ESET named Dolphin, has a wide range of spying capabilities, including monitoring drives and portable devices, exfiltrating files of interest, keylogging, taking screenshots, and stealing credentials from browsers. Its functionality is reserved for selected targets, to which the backdoor is deployed after initial compromise using less advanced malware. Dolphin abuses cloud storage services — specifically Google Drive — for Command and Control communication.

ScarCruft, also known as APT37 or Reaper, is an espionage group that has been operating since at least 2012. It primarily focuses on South Korea, but other Asian countries have also been targeted. ScarCruft seems to be interested mainly in government and military organizations, and companies in various industries linked to the interests of North Korea.

“After being deployed on selected targets, it searches the drives of compromised systems for interesting files and exfiltrates them to Google Drive. One unusual capability found in prior versions of the backdoor is the ability to modify the settings of victims’ Google and Gmail accounts to lower their security, presumably to maintain Gmail account access for the threat actors,” says ESET researcher Filip Jurčacko, who analyzed the Dolphin backdoor.

In 2021, ScarCruft conducted a watering-hole attack on a South Korean online newspaper focused on North Korea. The attack consisted of multiple components, including an Internet Explorer exploit and shellcode leading to a backdoor named BLUELIGHT.

“In the previous reports, the BLUELIGHT backdoor was described as the attack’s final payload. However, when analyzing the attack, we discovered through ESET telemetry a second, more sophisticated backdoor deployed on selected victims via this first backdoor. We named this backdoor Dolphin based on a PDB path found in the executable,” explains Jurčacko.

Since the initial discovery of Dolphin in April 2021, ESET researchers have observed multiple versions of the backdoor, in which the threat actors improved the backdoor’s capabilities and made attempts to evade detection.

While the BLUELIGHT backdoor performs basic reconnaissance and evaluation of the compromised machine after exploitation, Dolphin is more sophisticated and manually deployed only against selected victims. Both backdoors are capable of exfiltrating files from a path specified in a command, but Dolphin also actively searches drives and automatically exfiltrates files with interesting extensions.

The backdoor collects basic information about the targeted machine, including the operating system version, malware version, list of installed security products, username, and computer name. By default, Dolphin searches all fixed (HDD) and non-fixed drives (USBs), creates directory listings, and exfiltrates files by extension. Dolphin also searches portable devices, such as smartphones, via the Windows Portable Device API. The backdoor also steals credentials from browsers, and is capable of keylogging and taking screenshots. Finally, it stages this data in encrypted ZIP archives before uploading to Google Drive.

For more technical information about the latest ScarCruft APT group campaign, check out the blogpost “Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About ESET

For more than 30 years, ESET® has been developing industry-leading IT security software and services to protect businesses, critical infrastructure, and consumers worldwide from increasingly sophisticated digital threats. From endpoint and mobile security to endpoint detection and response, as well as encryption and multifactor authentication, ESET’s high-performing, easy-to-use solutions unobtrusively protect and monitor 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company that enables the safe use of technology. This is backed by ESET’s R&D centers worldwide, working in support of our shared future. For more information, visit www.eset.com or follow us on LinkedIn, Facebook, and Twitter.

Sanjeev Kant
Vistar Communications
+971 55 972 4623
email us here

You just read:

News Provided By

December 06, 2022, 08:03 GMT


EIN Presswire’s priority is source transparency. We do not allow opaque clients, and our editors try to be careful about weeding out false and misleading content.
As a user, if you see something we have missed, please do bring it to our attention. Your help is welcome. EIN Presswire, Everyone’s Internet News Presswire™,
tries to define some of the boundaries that are reasonable in today’s world. Please see our
Editorial Guidelines
for more information.





Source link

Share this…


  • Facebook


  • Twitter


  • Tumblr


  • Pinterest

Related

Share2Tweet1Share
Previous Post

ONE400 Helps Law Firms Grow Revenue and Increase Profit

Next Post

Ban Ki-moon Centre and PACJA Committed to Climate Change Adaptation

RelatedPosts

Visualize A Company’s External Attack Surfaces for Free
IT Industry

Visualize A Company’s External Attack Surfaces for Free

March 25, 2023
49
Global Machine Learning Infrastructure as a Service Market by Product & Service, Type, Key Players, & Application 2023
IT Industry

Global Machine Learning Infrastructure as a Service Market by Product & Service, Type, Key Players, & Application 2023

March 25, 2023
42
Dart Design unifies with Dart Digital to unveil the fusion of technology and services
IT Industry

Dart Design unifies with Dart Digital to unveil the fusion of technology and services

March 25, 2023
42
Fragnova introduces the RareForm Engine
IT Industry

Fragnova introduces the RareForm Engine

March 24, 2023
44
Product Information Management Market Research Report
IT Industry

Product Information Management Market Research Report

March 24, 2023
42
Pioneering AI Art Collection Ignites The Bitcoin Digital Art Movement with Magic Eden
IT Industry

Pioneering AI Art Collection Ignites The Bitcoin Digital Art Movement with Magic Eden

March 23, 2023
44
Next Post
Ban Ki-moon Centre and PACJA Committed to Climate Change Adaptation

Ban Ki-moon Centre and PACJA Committed to Climate Change Adaptation

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

WSCA News Store
  • iPhone 12 Pro Max NBC Store The Office Halloween Logo Case $24.97
  • The Georgian Feast: The Vibrant Culture and Savory Food of the Republic of Georgia $19.39
  • SENSORY GOODS Child Small Vinyl Weighted Blanket Made in America- 6lb Medium Pressure - Navy- Vinyl (48'' x 30'') Our Weighted Blankets Provide Comfort and Relaxation. $97.99
  • SadoTech Wireless Doorbells for Home, Apartments, Businesses, Classrooms, etc. - 1 Door Bell Ringer & 1 Plug-In Chime Receiver, Battery Operated, Easy-to-Use, Wireless Doorbell w/LED Flash, Gray $31.17
  • Life Will Be the Death of Me: . . . and you too! $12.99
  • Just My Size Women's T-Shirt, Plus Size Long Sleeve Cotton Tee, JMS Plus Size Scoop-Neck T-Shirt for Women $12.00
  • Ten Lessons for a Post-Pandemic World $8.55
  • Bundaloo Claw Machine Arcade Game - Electronic Mini Candy and Toy Grabber Dispenser for Kids - with Lights Sound & 4 Mini Plush Animals (Red) $41.82
  • What We Must Demand For Our Democracy to Survive: What Commitments Should Presidential Candidates Make in Writing Prior to the 2020 Election $3.99
  • MRSP Cosmetic Bag Makeup bags for women,Small makeup pouch Travel bags for toiletries waterproof Dead The Nightmare Before Christmas (The Starry Night) $7.99
  • Richard Hofstadter: Anti-Intellectualism in American Life, The Paranoid Style in American Politics, Uncollected Essays 1956-1965 (LOA #330) (Library of America) $45.00 $39.04
  • NBC Brooklyn Nine-Nine Amazing Detective Genius Sherpa Blanket-50 x 60" $69.95
  • NBC Brooklyn Nine-Nine Gina Knows Best Sherpa Blanket -50" x 60" $69.95
  • Placeholder Release Anger: How to Let Go of the Past and Live in the Now $0.00
  • Hanes Men's T-Shirts, Men's BeefyT Henley Shirts, Men's Cotton Long Sleeve Shirts $7.95
  • Our Time Is Now $18.00 $9.55
  • NBC The Office Mash-Up Sherpa Blanket - 37" X 57"-White $49.95
  • All in the Family: Seasons 1-5 $55.99
  • American Ninja Warrior Sherpa Blanket - 50" x 60" $69.95
  • Democracy Of A Madman: Mad Duet: Book 1 (Cult X Series 4) $4.99
  • Loungefly X Disney Nightmare Before Christmas Tarot Card Wallet $39.99
  • NBC The Office I Love You Like Jim Loves Pam Sherpa Throw Blanket - 37" x 57" $49.95
  • The End of America $24.95 $12.60
  • Ranger 15" Rubber Supersized Men's Overboots, Black (T369) $69.72
  • The Postmodern Pilgrim's Progress: An Allegorical Tale $17.99 $12.53
  • NBC The Office Minions Sherpa Blanket $49.95
  • On Tyranny: Twenty Lessons from the Twentieth Century $8.99
  • Monogram International NBC Nightmare Before Christmas / Jack Skellington Bust Bank $25.16
  • The Price of Peace: Money, Democracy, and the Life of John Maynard Keynes $53.18
  • Cotton High Waisted Soft Womens Underwear Breathable Panties, Multipack $25.99
  • News Channel
  • Agriculture, Farming & Forestry Industry
  • Amusement, Gaming & Casino
  • Automotive Industry
  • Aviation & Aerospace Industry
  • Banking, Finance & Investment Industry
  • Beauty & Hair Care
  • Book Publishing Industry
  • Building & Construction Industry
  • Business & Economy
  • Comedy
  • Companies
  • Conferences & Trade Fairs
  • Consumer Goods
  • Culture, Society & Lifestyle
  • Education
  • Electronics Industry
  • Emergency Services
  • Energy Industry
  • Entertainment
  • Environment
  • Food & Beverage Industry
  • Formula One
  • Furniture & Woodworking Industry
  • Gaming
  • Gifts, Games & Hobbies
  • Golf
  • Healthcare
  • Howto & Style
  • Human Rights
  • Insurance Industry
  • International Organizations
  • IT Industry
  • Law
  • Manufacturing
  • Media, Advertising & PR
  • Military Industry
  • Movie
  • Music
  • Natural Disasters
  • Politics
  • Real Estate & Property Management
  • Religion
  • Retail
  • Science
  • WSCA Sports

2023 WSCA News, an SCA Sunset Entertainment & Media Company. All Rights Reserved. Privacy Policy | Terms of Use

No Result
View All Result
  • News Channel
  • Agriculture, Farming & Forestry Industry
  • Amusement, Gaming & Casino
  • Automotive Industry
  • Aviation & Aerospace Industry
  • Banking, Finance & Investment Industry
  • Beauty & Hair Care
  • Book Publishing Industry
  • Building & Construction Industry
  • Business & Economy
  • Comedy
  • Companies
  • Conferences & Trade Fairs
  • Consumer Goods
  • Culture, Society & Lifestyle
  • Education
  • Electronics Industry
  • Emergency Services
  • Energy Industry
  • Entertainment
  • Environment
  • Food & Beverage Industry
  • Formula One
  • Furniture & Woodworking Industry
  • Gaming
  • Gifts, Games & Hobbies
  • Golf
  • Healthcare
  • Howto & Style
  • Human Rights
  • Insurance Industry
  • International Organizations
  • IT Industry
  • Law
  • Manufacturing
  • Media, Advertising & PR
  • Military Industry
  • Movie
  • Music
  • Natural Disasters
  • Politics
  • Real Estate & Property Management
  • Religion
  • Retail
  • Science
  • WSCA Sports

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist