[ << ALL_FEED ]

APT-C-60, or DarkHotel

More in General

APT-C-60, aka DarkHotel

💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that post via the link. At the time, we mentioned that research on this topic would be released soon. Yes, it has finally happened!

🕵️‍♂️ We hasten to remind you about the APT-C-60 group. This is a cyberespionage group first identified in 2021. It targets industrial companies, particularly semiconductor manufacturers in South Korea, as well as entities in East Asia.

The group uses phishing emails with malicious attachments and exploits vulnerabilities in software (including vulnerabilities in WPS Office) to deploy malware called SpyGlace.

Recently, the group has been using vulnerabilities in WPS Office products (CVE-2024-7262), but earlier in their attacks they used a virtual disk. In September 2024, we noticed one of the new disks and decided it would be useful to report on this.

Other researchers link this group to a common cluster called DarkHotel. We will show where this connection comes from and reaffirm that researching metadata is important.

☕️ The new research can be found on our website.

Enjoy the read!

#TI #news #APT
@ptescalator

More from ti_author

More from ti_author

More in General