Source |
The Hacker News |
Identifiant |
7662160 |
Date de publication |
2022-10-24 11:55:00 (vue: 2022-10-24 07:05:34) |
Titre |
SideWinder APT Using New WarHawk Backdoor to Target Entities in Pakistan |
Texte |
SideWinder, a prolific nation-state actor mainly known for targeting Pakistan military entities, compromised the official website of the National Electric Power Regulatory Authority (NEPRA) to deliver a tailored malware called WarHawk.
"The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike, incorporating new TTPs such as KernelCallBackTable injection |
Notes |
|
Envoyé |
Oui |
Condensat |
actor apt as kernelcallbacktable authority backdoor called warhawk cobalt compromised contains deliver discovered electric entities incorporating injection known mainly malicious malware military modules nation national nepra new newly official pakistan power prolific regulatory sidewinder state strike such tailored target targeting ttps using various warhawk website |
Tags |
Malware
|
Stories |
APT-C-17
|
Move |
|