The recently discovered Worok cyberespionage group has been hacking high-profile governments and companies in Asia since at least 2020 using a combination of custom and existing malicious tools.
See also: Los Angeles Unified School District: Hit by ransomware

The threat group, which is being tracked as Worok by ESET security researchers who first identified it, has attacked targets located in Africa and the Middle East.
To date, the Worok group has been linked to attacks against telecommunications, banks, shipping and energy companies, as well as military, government and public entities.
In late 2020, Worok targeted a telecommunications company in East Asia, a bank in Central Asia, a shipping industry company in Southeast Asia, a government entity in the Middle East, and a private company in southern Africa.
ESET once again linked the group to new attacks against an energy company in Central Asia and a public sector entity in Southeast Asia .
Although the group used ProxyShell exploits to gain initial access to its victims ' networks , the initial access agent remains unknown for most of its breaches.

See also: QNAP fixes zero-day bug used by DeadBolt ransomware
The Worok group's malicious toolkit includes two loaders, a C++ loader known as CLRLoad and a C# loader called PNGLoad, helping attackers hide malware payloads in PNG image files using steganography.
While ESET has yet to recover one of the final payloads delivered in the group's attacks, it has identified a new PowerShell backdoor dubbed PowHeartBeat, which has replaced CLRLoad in incidents observed since February 2022 as the tool designed to launch PNGLoad on compromised systems.

See also: Sextortion ring dismantled by Interpol, what to watch out for
PowHeartBeat has a wide range of capabilities, including manipulating files and executing commands or processes, as well as sending or receiving files to and from victims' devices.
Information source: bleepingcomputer.com
