Security News > 2023 > March > Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX Malware
Security vulnerabilities in remote desktop programs such as Sunlogin and AweSun are being exploited by threat actors to deploy the PlugX malware.
AhnLab Security Emergency Response Center, in a new analysis, said it marks the continued abuse of the flaws to deliver a variety of payloads on compromised systems.
The modular malware has been extensively put to use by threat actors based in China, with new features continuously added to help perform system control and information theft.
In the attacks observed by ASEC, successful exploitation of the flaws is followed by the execution of a PowerShell command that retrieves an executable and a DLL file from a remote server.
This executable is a legitimate HTTP Server Service from cybersecurity company ESET, which is used to load the DLL file by means of a technique called DLL side-loading and ultimately run the PlugX payload in memory.
"PlugX operators use a high variety of trusted binaries which are vulnerable to DLL Side-Loading, including numerous anti-virus executables," Security Joes noted in a September 2022 report.
News URL
https://thehackernews.com/2023/03/hackers-exploiting-remote-desktop.html
Related news
- FIN7 hackers launch deepfake nude “generator” sites to spread malware (source)
- Microsoft fixes Remote Desktop issues caused by Windows Server update (source)
- N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware (source)
- Perfctl malware strikes again as crypto-crooks target Docker Remote API servers (source)
- Amazon seizes domains used in rogue Remote Desktop campaign to steal data (source)
- Russian spies use remote desktop protocol files in unusual mass phishing drive (source)
- North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS (source)
- North Korean hackers use new macOS malware against crypto firms (source)
- Unpatched Mazda Connect bugs let hackers install persistent malware (source)
- North Korean Hackers Target macOS Using Flutter-Embedded Malware (source)