Source |
CSO |
Identifiant |
6790810 |
Date de publication |
2022-09-08 14:14:00 (vue: 2022-09-08 22:05:42) |
Titre |
North Korean state-sponsored hacker group Lazarus adds new RAT to its malware toolset |
Texte |
Security researchers have discovered a new remote access Trojan (RAT) being used in attack campaigns this year by Lazarus, a threat actor tied to the North Korean government. The new RAT has been used alongside other malware implants attributed to Lazarus and it's mainly used in the first stages of an attack.Dubbed MagicRAT, the new Lazarus malware program was developed using Qt, a framework commonly used to develop graphical user interfaces for cross-platform applications. Since the Trojan doesn't have a GUI, researchers from Cisco Talos believe the reason for using Qt was to make detection harder.To read this article in full, please click here |
Notes |
|
Envoyé |
Oui |
Condensat |
access actor adds alongside applications article attack attributed been being believe campaigns cisco click commonly cross detection develop developed discovered doesn dubbed first framework from full government graphical group gui hacker harder has have here implants interfaces its korean lazarus magicrat mainly make malware new north other platform please program rat read reason remote researchers security since sponsored stages state talos threat tied toolset trojan used user using year |
Tags |
Malware
Threat
|
Stories |
APT 38
|
Move |
|