Security News > 2023 > August > Cisco Talos Research: New Lazarus Group Attack Malware Campaign Hits UK & US Businesses
The Cisco Talos report exposes new malware used by the group to target Internet backbone infrastructure and healthcare organizations in the U.K. and the U.S. Two reports from cybersecurity company Cisco Talos provide intelligence about a new attack campaign from the North Korean threat actor Lazarus.
The researchers observed the Lazarus group successfully compromise an internet backbone infrastructure provider in the U.K. in early 2023, deploying a new malware dubbed QuiteRAT. The initial compromise was done via exploitation of the CVE-2022-47966 vulnerability, which affects Zoho's ManageEngine ServiceDesk.
Once the malware has been executed, it starts sending initial information about the system to its command-and-control server and waits for an answer, which might be a direct command to the malware or a Microsoft Windows command line to be executed via the cmd.
Figure A. The Lazarus group's new arsenal of malware.
Lazarus has used various malware in this attack campaign: QuiteRAT, CollectionRAT, DeimosC2 and malicious Plink.
Although the group makes a lot of changes to its arsenal, the North Korean state-sponsored Lazarus threat actor "Continues to use much of the same infrastructure despite those components being well-documented by security researchers over the years," according to Cisco Talos.
News URL
https://www.techrepublic.com/article/cisco-talos-lazarus-group-new-malware/
Related news
- YARA: Open-source tool for malware research (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- Healthcare attacks spread beyond US – just ask India's Star Health (source)
- US and UK govts warn: Russia scanning for your unpatched vulnerabilities (source)
- China again claims Volt Typhoon cyber-attack crew was invented by the US to discredit it (source)
- 99% of UK Businesses Faced Cyber Attacks in the Last Year (source)
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active Attack (source)
- Cisco fixes VPN DoS flaw discovered in password spray attacks (source)
- Emergency patch: Cisco fixes bug under exploit in brute-force attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-18 | CVE-2022-47966 | Unspecified vulnerability in Zohocorp products Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. | 9.8 |