Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
US Media, Retailers Targeted by New SparklingGoblin APT
#1
Information 
Quote:An emerging international cybergang is broadening its targets to include North American media firms, universities and one computer retailer. The advanced persistent threat (APT) group is new, according to researchers who dubbed it SparklingGoblin. Also new is a novel backdoor technique, called SideWalk, used by the APT to penetrate cybersecurity defenses.
 
SparklingGoblin, according to ESET researchers who named and discovered the crime group and backdoor, is an offshoot of another APT Winnti Group, first identified in 2013 by Kaspersky. ESET also said in a Tuesday report that the SideWalk backdoor is similar to one used by Winnti called Crosswalk.
 
Crosswalk and SideWalk, according the ESET, are both “modular backdoors used to exfiltrate system information and that can run shellcode sent by the C&C server.”

The group, which previously focused attacks on sectors in Macao, Hong Kong and Taiwan in 2020, is still active targeting victims via spearphishing campaigns that include a range of malicious payloads including PDFs (with LNK files), decoy Adobe Flash Players and booby-trapped JavaScript files. Researchers also theorize that initial compromises of victims may also include waterholes.

ESET said it first became aware of SparklingGoblin in May 2020 when tracking the Winnti APT. Researchers said that’s when they stumbled upon an unusual malware packer used to deliver malicious payloads to victims. An analysis of the malware inside the packer revealed “samples containing artifacts from both the Equation Group and Winnti Group,” researchers wrote in an analysis.

Read more: US Media, Retailers Targeted by New SparklingGoblin APT
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
How to turn off App Promotions in Windo...
disable app promotio...marcojanson42 — 09:42
Microsoft Edge 125.0.2535.51
Version 125.0.2535...harlan4096 — 06:59
NoVirusThanks OSArmor 1.9.9
OSArmor v1.9.9 rel...harlan4096 — 06:00
INTEL Arc Graphics 31.0.101.5522
Highlights Gami...harlan4096 — 05:58
Malwarebytes 5.1.4.112
We have released a...Mohammad.Poorya — 21:27

[-]
Birthdays
Today's Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
Upcoming Birthdays
avatar (37)axuben
avatar (38)ihijudu
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)GregoryRog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>