Russian military-industrial complex exposed to unusual hacker attacks 17:58

Hacker group Core Werewolf attacked Russian military-industrial organizations and critical information infrastructure organizations. About a month ago, attackers began using a new self-developed bootloader in their operations, written in the unpopular Autoit programming language, making it harder to detect. The head of the Threat Intelligence department at Bi.Zone told socialbites.ca about this.

Representatives of Core Werewolf sent phishing emails containing links to RAR archives. These also included self-extracting files (SFX). Each of them contains a malicious script (program code – “socialbites.ca”), a legitimate interpreter necessary for its execution (allows you to run the code as a program without preliminary compilation – “socialbites.ca”), as well as a distracting document in PDF format . If the user opened the archive to view the “documents”, the contents of the SFX file were automatically extracted to the temporary file storage (TEMP) folder. The translator then launched the bootloader, a service that installs malware on the compromised device.

“The detectability of used vehicles is constantly increasing. In this context, criminals are making changes to their arsenal in the hope that it will allow them to remain undetected in the victim’s IT infrastructure for longer. The less a tool is used in attacks (such as the Autoit language in this case), the greater the chance that attackers will not be able to recognize it,” Skulkin told socialbites.ca.

Since June this year, the group has also begun experimenting with methods of distributing malicious files. Previously, Core Werewolf sent RAR archives with phishing letters only via email, now target organizations began to receive messages containing malicious attachments in instant messengers, mostly Telegram.

To protect against Core Werewolf attacks, Russian companies are recommended to use up-to-date security tools that can work with software written in the Autoit programming language.

Core Werewolf was first noticed during attacks on the Russian Federation in the summer of 2021.

Russians before said About the most popular scam schemes of 2024.

What are you thinking?



Source: Gazeta

Popular

More from author

The Ministry of Foreign Affairs announced the equality of the US and Russia in the field of information security 18:06

Russia is not behind the US in the field of information security - this has been proven in a special military operation (SV). Reporting...

China suspended measures against 17 American companies 17:39

China suspended measures against 17 American companies included in the list of unreliable assets. This was reported by Ria Novosti to the PRC Ministry...

The young Russian beat his mother with a trophy and barely did not drown her 18:04

A resident of the Kaliningrad region beat his mother with a trophy and tried to drown, Reported Regional Water TFR. The conflict between relatives occurred...