HomeSecurityLazarus hackers use new LightlessCan malware

Lazarus hackers use new LightlessCan malware

Lazarus hackers , linked to the North Korean government, are responsible for an attack against a Spanish aerospace company, using a new and dangerous malware called LightlessCan .

Lazarus hackers

ESET claims that this attack is reminiscent of previous attacks by the Lazarus group.

As in other campaigns, the Lazarus hackers used LinkedIn to contact employees of the unnamed Spanish company. The hackers posed as recruiters from Meta and suggested that victims download two files. These files contained malicious code that allowed the installation of malware.

See also: Sony: Data breach affects thousands of employees

ESET states that the goal of the attack was espionage . “ The theft of the know-how of an aerospace company is consistent with the long-term goals of the Lazarus hackers ,” wrote Peter Kálnai , senior malware researcher at ESET.

The Lazarus group has attacked many high- profile, including organizations in the aerospace, chemical, and other critical industries. The hackers have also carried out several crypto.

Lazarus hackers: New malware

In previous attacks, the Lazarus group used a remote access trojan known as BlindingCan. However, according to ESET, the attack on the Spanish aerospace company used an upgraded malware tool called “LightlessCan,” which supports 68 malicious commands, although at present, 43 appear to be working.

See also: Gmail: Strengthens defenses against phishing and malware from 2024

ESET analysts believe that LightlessCan is based on the source code of BlindingCan, although there may be some minor differences.

LightlessCan malware

The LightlessCan malware from Lazarus hackers can mimic Windows, such as ping, ipconfig, systeminfo, sc, net, and others similar to it, with a hardcoded string “The operation completed successfully”, to cause confusion and prevent the RAT from being detected.

Additionally, the security firm observed that the commands were executed covertly within the RAT itself rather than running on the system. This offers a significant advantage, allowing it to evade real-time monitoring solutions.

According to ESET researchers, while the LightlessCan malware was first observed in the attack on the Spanish aerospace company, it is not the only time researchers have spotted it. The company believes that LightlessCan is likely to become the main tool of the Lazarus hackers.

See also: Gay furries: They claim they breached NATO and stole 3,000 files

Lazarus hackers have become known for their amazing ability to adapt and evolve. As one of the most active cybercriminal groups, Lazarus focuses on espionage and theft . Their extensive knowledge of security systems allows them to penetrate the most complex networks and gain access to sensitive data. With the new malware, the Lazarus Group shows that it is capable of launching even more extensive attacks against companies and organizations around the world. 

Source: www.theregister.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS