North Korea debuts new Electricfish malware in Hidden Cobra campaigns
#1
Quote:The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) have released a joint security advisory warning of a new strain of malware being used in North Korean cyberattacks.
 
Dubbed Electricfish, the malware was uncovered while the departments were tracking the activities of Hidden Cobra, a threat group believed to be state-sponsored and backed by the North Korean government.

Also known as the Lazarus group, Hidden Cobra has been connected to a variety of attacks against financial institutions, critical industrial players, and targets chosen for valuable intellectual property worldwide.
 
The description of Electricfish is based on one malicious 32-bit Windows executable. After reverse engineering the sample, the malware was found to contain a custom protocol which permits traffic to be funneled between source and destination IP addresses. Electricfish is, therefore, able to shift traffic through proxies by the attackers to reach outside of a victim network.

"The malware can be configured with a proxy server/port and proxy username and password," the advisory reads. "This feature allows connectivity to a system sitting inside of a proxy server, which allows the actor to bypass the compromised system's required authentication to reach outside of the network."

SOURCE: https://www.zdnet.com/article/north-kore...campaigns/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Mohammad.Poorya
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.18  Added op...Kool — 08:37
Mozilla Firefox Browser 149.0
Mozilla Firefox Br...harlan4096 — 08:09
AxCrypt 3.0.0.82
AxCrypt 3.0.0.82: ...harlan4096 — 08:07
uBOLite 2026.323.2044 (already available...
uBOLite 2026.323.2...harlan4096 — 08:06
AnyDesk 9.6.12 for Windows
Version 9.6.12 for...harlan4096 — 08:05

[-]
Birthdays
Today's Birthdays
avatar (43)artmaGoork
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>