Skip to main content

Lazarus hackers target Dell drivers with new rootkit

It seems as blockchain developers and artists are not the only ones Lazarus Group targets with fake job offers. 

Aerospace experts and political journalists in Europe have also been recently targeted with the same form of social engineering attacks, with the same goal - corporate espionage and data exfiltration from business devices. 

What makes this campaign unique, however, is the fact that the targets were infected with legitimate drivers.

Disabling monitoring mechanisms

Cybersecurity researchers from ESET have recently seen Lazarus Group - a known North Korean state-sponsored threat actor, approaching the abovementioned individuals with fake job offers from Amazon. 

Those that accepted the offer, and downloaded fake job description PDF files, have had an old, vulnerable Dell driver installed. That opened the doors for the threat actors to compromise the endpoints, and exfiltrate whatever data they were looking for.

"The most notable tool delivered by the attackers was a user-mode module that gained the ability to read and write kernel memory due to the CVE-2021-21551 vulnerability in a legitimate Dell driver," ESET said. "This is the first ever recorded abuse of this vulnerability in the wild."

This gave Lazarus the ability to disable some of Windows’ monitoring mechanisms, allowing it to tweak the registry, file system, process creation, event tracing, and similar, ESET further said. This “basically blinded security solutions in a very generic and robust way."

CVE-2021-21551 is a vulnerability that encompasses five different flaws that were flying under the radar for 12 years, before Dell finally fixed it, BleepingComputer reminds. Lazarus used it to deploy its HTTP(S) backdoor “BLINDINGCAN”, a remote access trojan (RAT) that is able to execute various commands, take screenshots from the compromised endpoints, create and terminate various processes, exfiltrate data and system information, and more.

The threat actor also used the vulnerabilities to deploy FudModule Rootkit, an HTTP(S) uploader, as well as compromised open-source apps wolfSSL and FingerText.

Via: BleepingComputer



Source: TechRadar

Popular posts from this blog

Uber Eats exits seven markets, transfers one as part of competitive retooling

Uber Eats is pulling out of a clutch of markets — shuttering its on-demand food offering in the Czech Republic, Egypt, Honduras, Romania, Saudi Arabia, Uruguay and Ukraine. It’s also transferring its Uber Eats business operations in the United Arab Emirates (UAE) to Careem, its wholly owned ride-hailing subsidiary that’s mostly focused on the Middle East. “Consumers and restaurants using the Uber Eats app in the UAE will be transitioned to the Careem platform in the coming weeks, after which the Uber Eats app will no longer be available,” it writes in a regulatory filing detailing the operational shifts. “These decisions were made as part of the Company’s ongoing strategy to be in first or second position in all Eats markets by leaning into investment in some countries while exiting others,” the filing adds. An Uber spokesman said the changes are not related to the coronavirus pandemic but rather related to an ongoing “strategy of record” for the company to hold a first or s

Keep your Oculus Quest controllers going strong with these batteries

The Touch Controllers for the Oculus Quest 2 ship with one disposable AA battery each, but once those run out of juice, you should invest in the best Oculus Quest 2 replacement batteries to fill in for them. While the Touch Controllers last much longer than the headset's limited battery, it's still wise to invest in some rechargeable batteries or a stack of disposable batteries to stop your VR sessions from getting disrupted. Here are the batteries and chargers we recommend for your Oculus Touch controllers. Best rechargable batteries + charger Panasonic K-KJ55MCA4BA 3 Hour Quick Charger with 4 AA eneloop Rechargeable Batteries Staff Pick These rechargeable batteries store up to 2,000 mAh of power and can be recharged up to 2,100 times. They can be charged completely from dead or partially charged without damaging the energy storage memory. We recommend buying them with the quick charger accessory, which will get your AAs recharged in no time, but you can also purchas

These Android games support Bluetooth controllers and they're better for it

Gaming is simply better with a controller in your hands. Gaming on Android typically requires you to settle for using touchscreen controls. However, some gracious game developers take the time and effort to add support for Bluetooth gamepads— and we love them for it. Since so few games provide this feature, we've taken the time to test and compiled our list of the best games that let you play with the best Bluetooth controller in your hands. We'd also recommend getting a Style Ring or PopSocket which can help prop your phone up at a good angle for gaming. You might recognize some of these games from the best Android games roundup and for good reason. But you're here for the best games with controller support, after all, so here I present to you the best you can find on the Play Store. The games Call of Duty Mobile GRID Autosport Tesla vs Lovecraft Evoland 2 Horizon Chase World Tour Riptide GP: Renegade Modern Combat 5: Blackout GTA: San Andreas Oceanhor

What ancient advice can teach us about AI

Artificial Intelligence (AI) is everywhere. Siri, Alexa and Google Assistant have become indispensable to millions of users. Tesla Autopilot has the potential to change driving forever. And IBM Watson took a new job providing big data solutions to corporations after its first job was in jeopardy. Those are just the most prominent examples. Helpful applications of AI are being deployed in a broad spectrum of industries, but AI also has the potential to be misused. About the author  Jason Egnal is Chief Marketing Officer at Zenfolio . His background spans a variety of industries, including SaaS, AI, Fintech and Consumer Electronics.  Zenfolio, the website builder and photo sharing site , recently introduced technology that applies AI to assist photographers in selecting the best photos from the thousands of shots typically taken during a photo session. The advanced image recognition technology is tremendously powerful and can make photographers more efficient than they ever d