Thứ Hai, Tháng Hai 6, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Chinese hackers use new stealth infection chain to deploy malware LODEINFO

2 Tháng Mười Một, 2022
in Tech
0
Chinese hackers use new stealth infection chain to deploy malware LODEINFO
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Chinese state-sponsored threat actor Stone Panda has been observed using a new stealth infection chain in attacks against Japanese entities.

The targets included media, diplomatic, government and public sector organizations and think tanks in Japan, according to the Kaspersky report.

Stone Panda, also known as APT10, Bronze Riverside, Cicada, and Potassium, is a cyber espionage group known for their infiltrations against organizations identified as strategically significant to China. The blackmailer is said to have been active since at least 2009.

Latest set of attacks, observed from March to June 2022, related to file usage Microsoft The bogus word and self-extracting archive (SFX) in RAR format were spread via phishing email, leading to the execution of a backdoor called LODEINFO.

While maldoc requires users to enable macros to trigger the killchain, the June 2022 campaign was found to have removed this method to switch to an SFX file that, when executed, displays a forged Word document in malicious to conceal malicious activities.

The macro, once activated, drops a ZIP archive containing two files, one of which (“NRTOLF.exe”) is a legitimate executable from the K7Security Suite software that is then used to load a Rogue DLL (“K7SysMn1.dll”) via the payload DLL.

Besides the security application abuse, Kaspersky said it also discovered another initial infection method in June 2022, in which a password-protected Microsoft Word file acts as a link to provide an unfiltered downloader called DOWNIISSA with macros enabled.

Cybersecurity company Russia says: “The embedded macro will generate the DOWNIISSA shell code and inject it into the current process (WINWORD.exe).

DOWNIISSA is configured to communicate with a hardcoded remote server, use it to retrieve LODEINFO’s encrypted BLOB payload, a backdoor capable of executing arbitrary shellcode, taking screenshots and exfiltrate the files back to the server.

Malware This version, first seen in 2019, has undergone many improvements, with Kaspersky identifying six different versions in March, April, June and September 2022.

Changes include enhanced dodging techniques for flying under the radar, halting execution on machines with the “en_US” language, modifying the list of supported commands, and expanding support for the architecture. 64-bit by Intel.

“LODEINFO malware is updated very frequently and continues to actively target Japanese organizations,” the researchers concluded.

“Updated and improved TTPs in LODEINFO and related malware […] indicates that attackers are particularly focused on making it more difficult for security researchers to detect, analyze, and investigate. “

Related Posts

Previous Post

Experience of traveling to India for the first time safely and beautiful scenery

Next Post

Top 10 best online image sharpening software and websites in 2022

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Top 10 best online image sharpening software and websites in 2022

Top 10 best online image sharpening software and websites in 2022

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem