{"id":166426,"date":"2023-10-02T08:57:32","date_gmt":"2023-10-02T03:27:32","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=166426"},"modified":"2023-10-02T08:57:32","modified_gmt":"2023-10-02T03:27:32","slug":"lazarus-new-malware-can-now-bypass-detection-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/lazarus-new-malware-can-now-bypass-detection-crypto-news\/","title":{"rendered":"Lazarus\u2019 new malware can now bypass detection &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div data-v-ff33fc9a=\"\">\n<p>North Korean hacking collective Lazarus Group has been using a new type of \u201csophisticated\u201d malware as part of its fake employment scams \u2014 which researchers warn is far more challenging to detect than its predecessor.<\/p>\n<p><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company\/\">According<\/a> to a Sept. 29 post from ESET\u2019s senior malware researcher Peter K\u00e1lnai, while analyzing a recent fake job attack against a Spain-based aerospace firm, ESET researchers discovered a publicly undocumented backdoor named LightlessCan. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/ESET?src=hash&amp;ref_src=twsrc%5Etfw\">#ESET<\/a> researchers unveiled their findings about an attack by the North Korea-linked <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/APT?src=hash&amp;ref_src=twsrc%5Etfw\">#APT<\/a> group <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/Lazarus?src=hash&amp;ref_src=twsrc%5Etfw\">#Lazarus<\/a> that took aim at an aerospace company in Spain.<\/p>\n<p>\u25b6\ufe0f Find out more in a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/WeekinSecurity?src=hash&amp;ref_src=twsrc%5Etfw\">#WeekinSecurity<\/a> video with <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/TonyAtESET?ref_src=twsrc%5Etfw\">@TonyAtESET<\/a>. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/M94J200VQx\">pic.twitter.com\/M94J200VQx<\/a><\/p>\n<p>\u2014 ESET (@ESET) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ESET\/status\/1707751628340695202?ref_src=twsrc%5Etfw\">September 29, 2023<\/a><\/p><\/blockquote>\n<p>The Lazarus Group\u2019s fake job scam typically involves tricking victims with a potential offer of employment at a well-known firm. The attackers would entice victims to download a malicious payload masqueraded as documents to do all sorts of damage. <\/p>\n<p>However, K\u00e1lnai says the new LightlessCan payload is a \u201csignificant advancement\u201d compared to its predecessor BlindingCan.<\/p>\n<p>\u201cLightlessCan mimics the functionalities of a wide range of native Windows commands, enabling discreet execution within the RAT itself instead of noisy console executions.\u201d<\/p>\n<p>\u201cThis approach offers a significant advantage in terms of stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools,\u201d he said. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">\ufe0f\u200d\u2642\ufe0f Beware of fake LinkedIn recruiters! Find out how Lazarus group exploited a Spanish aerospace company via trojanized coding challenge. Dive into the details of their cyberespionage campaign in our latest <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/WeLiveSecurity?src=hash&amp;ref_src=twsrc%5Etfw\">#WeLiveSecurity<\/a> article. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/ESET?src=hash&amp;ref_src=twsrc%5Etfw\">#ESET<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/ProgressProtected?src=hash&amp;ref_src=twsrc%5Etfw\">#ProgressProtected<\/a><\/p>\n<p>\u2014 ESET (@ESET) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ESET\/status\/1707707211714064653?ref_src=twsrc%5Etfw\">September 29, 2023<\/a><\/p><\/blockquote>\n<p>The new payload also uses what the researcher calls \u201cexecution guardrails\u201d \u2014 ensuring that the payload can only be decrypted on the intended victim\u2019s machine, thereby avoiding unintended decryption by security researchers. <\/p>\n<p>K\u00e1lnai said that one case that involved the new malware came from an attack on a Spanish aerospace firm when an employee received a message from a fake Meta recruiter named Steve Dawson in 2022.<\/p>\n<p>Soon after, the hackers sent over the two simple coding challenges embedded with the malware.\u00a0<\/p>\n<figure><figcaption style=\"text-align: center\"><em>The initial contact by the attacker impersonating a recruiter from Meta. Source: WeLiveSecurity.<\/em><\/figcaption><\/figure>\n<p>Cyberespionage was the main motivation behind <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/north-korea-s-lazarus-behind-years-of-crypto-hacks-in-japan-police\">Lazarus Group\u2019s attack<\/a> on the Spain-based aerospace firm, he added.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/lazarus-group-safeguard-cryptocurrency-steps\"><strong><em>3 steps crypto investors can take to avoid hacks by the Lazarus Group<\/em><\/strong><\/a><\/p>\n<p>Since 2016, North Korean hackers have <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/north-korean-crypto-hacks-down-but-could-change-overnight-chainalysis\">stolen an estimated $3.5 billion from cryptocurrency projects<\/a>, according to a Sept. 14 report by blockchain forensics firm Chainalysis.<\/p>\n<p>In September 2022, cybersecurity firm SentinelOne warned of a fake job scam on LinkedIn, offering potential victims a job at Crypto.com as part of a campaign dubbed \u201cOperation Dream Job.&#8221;\u00a0<\/p>\n<p>Meanwhile, the United Nations has beetrying to curtail North Korea\u2019s cybercrime tactics at the international level \u2014 as it is <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.un.org\/pga\/76\/wp-content\/uploads\/sites\/101\/2022\/06\/220602-PSC-letter-special-report-to-GA-Signed-package.pdf\">understood<\/a> North Korea is using the stolen funds to support its nuclear missile program.<\/p>\n<p><strong><em>Magazine:<\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/3-4-billion-bitcoin-popcorn-tin-silk-road-hacker\/\"><strong><em> <\/em><\/strong><strong><em>$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker\u2019s story<\/em><\/strong><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>North Korean hacking collective Lazarus Group has been using a new type of \u201csophisticated\u201d malware as part of its fake employment scams \u2014 which researchers warn is far more challenging to detect than its predecessor. According to a Sept. 29 post from ESET\u2019s senior malware researcher Peter K\u00e1lnai, while analyzing a recent fake job attack [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":166427,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[235,203,210,234,231,232,237,238,236,233],"class_list":["post-166426","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-bitcoin","tag-crypto-currency","tag-elon-musk","tag-ethereum","tag-hyperledger","tag-ibm","tag-mining","tag-nodes","tag-spacex","tag-tesla"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/166426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=166426"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/166426\/revisions"}],"predecessor-version":[{"id":166429,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/166426\/revisions\/166429"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/166427"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=166426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=166426"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=166426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}