North Korean hackers Kimsuky are exploiting ScreenConnect vulnerabilities , specifically CVE-2024-1708 and CVE-2024-1709, to infect targets with the new ToddleShark malware .

Kimsuky (also known as Thallium and Velvet Chollima) are state-sponsored hackers, known for cyberespionage attacks on organizations and governments.
The two vulnerabilities exploited by hackers allow authentication bypass and remote code execution and were disclosed on February 20, 2024, when ConnectWise urged ScreenConnect customers to upgrade to version 23.9.8 or later.
According to a forthcoming Kroll shared with BleepingComputer, the Kimsuky hackers' ToddleShark malware exhibits polymorphic characteristics and is designed for long-term espionage and intelligence gathering.
ToddleShark uses legitimate Microsoft binaries to hide itself and performs registry modifications to reduce security. It also creates permanent access via scheduled tasks and then begins stealing data.
See also: Stuxnet-like attack via online PLC malware
ToddleShark malware: Details
Kroll analysts believe that ToddleShark is a new variant of the BabyShark and ReconShark frequently used by Kimsuky hackers. These backdoors have been used to target government organizations, research centers, universities, and think tanks in the United States, Europe, and Asia.
North Korean hackers initially gain access to vulnerable ScreenConnect endpoints by exploiting two vulnerabilities. As previously mentioned, the vulnerabilities allow for authentication bypass and code execution.
Kimsuky then uses legitimate Microsoft binaries, such as mshta.exe, to execute malicious scripts, combining the activities with normal system processes.
The ToddleShark malware then changes the VBAWarnings keys in the Windows Registry to allow macros to run in various versions of Microsoft Word and Excel without generating alerts.
Scheduled tasks are created to establish persistence by periodically (every minute) executing the malicious code.
See also: Pro-Hamas hackers target Israel with BiBi malware
ToddleShark malware regularly collects system information from infected devices:
- Hostname
- System configuration details
- User accounts
- Active user sessions
- Network configurations
- Installed security software
- All current network connections
- Number of processes running
Finally, ToddleShark encodes the collected information and sends it to the command and control (C2) of the Kimsuky hackers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ToddleShark: A Polymorphic Malware
ToddleShark is a polymorphic malware, which allows it to evade detection in many cases and make analysis more difficult. ToddleShark achieves this through a variety of techniques.
For example, it uses randomly generated functions and variable names in the obfuscated VBScript used in the initial infection. This makes static detection more difficult. Also, large amounts of hexadecimal encoded code scattered with unwanted code can make the malware payload appear harmless or non-executable.
Additionally, the ToddleShark malware uses randomized strings and [functional] code positioning, changing its structural pattern enough to make signature-based detection difficult.
To protect against malware like ToddleShark, an organization should keep its device software and operating system up to date. These updates often include security patches that can prevent malware from entering the system.
See also: Calendly Link spreads malware to Mac devices
Additionally, users should be cautious about the emails and file attachments they receive. Malware is often spread through phishing attacks, where attackers try to trick users into clicking on harmful links or opening dangerous attachments.
Using a reliable program antivirus is also crucial. These programs can detect and remove malware before it can cause damage to the system.
Finally, regularly backing up important data can help prevent data loss in the event of an attack.
Source: www.bleepingcomputer.com
