Chinese -speaking hackers Earth Lusca are using a new backdoor, called KTLVdoor, as part of a cyberattack against a Chinese company.

The malware is written in Golang and, as such, is a cross-platform tool, capable of targeting Windows and Linux systems.
See also: Godzilla Fileless Backdoor exploits Atlassian Confluence vulnerability
According to researchers at Trend Micro, the KTLVdoor backdoor masquerades as system utilities and allows attackers to do various things, such as manipulate files, execute commands, and remotely scan ports. Some of the tools impersonated by KTLVdoor include sshd, Java, SQLite, bash, and edr-agent. The malware is distributed in the form of a dynamic-link library (.dll) or shared object (.so).
Perhaps most unusual in this campaign is the discovery of more than 50 command-and-control (C&C) servers hosted by Chinese company Alibaba. Researchers have observed them communicating with various malware variants, which suggests that the infrastructure could be used by various Chinese hackers.
The Earth Lusca hackers have been active since at least 2021 and have targeted entities in both the public and private sectors across Asia, Australia, Europe, and North America.
See also: PHP vulnerability used to install Msupedge backdoor
The KTLVdoor backdoor appears to be the latest addition to the Chinese-speaking group's arsenal. After infection, the malware begins communicating with the C&C server, awaiting further instructions to execute on the compromised computer. Supported commands allow it to download/upload files, check the file system, launch an interactive shell, execute shellcode, and initiate scanning.
At this time, we do not know how the KTLVdoor backdoor is distributed and whether it has been used to target other entities beyond the Chinese company.

Backdoor protection
Organizations can protect their networks from the KTLVdoor backdoor by implementing various security. First, it is important to keep their systems up to date. This means that they should regularly install the latest updates and security patches on all operating systems and applications.
See also: New Windows Backdoor BITSLOTH exploits BITS for covert communication
Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.
Staff training is also critical to avoiding the KTLVdoor backdoor. Employees need to be aware of the risks associated with cybersecurity and the tactics used by attackers, such as phishing .
Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
