Tag

Kimsuky

All articles tagged with #kimsuky

cybersecurity1 year ago

"ScreenConnect Flaws Used to Deploy ToddlerShark Malware"

North Korean threat actors have exploited vulnerabilities in ConnectWise ScreenConnect to deploy a new malware called TODDLERSHARK, which overlaps with known Kimsuky malware such as BabyShark and ReconShark. The malware is designed to capture and exfiltrate sensitive information about compromised hosts and exhibits polymorphic behavior to evade detection. South Korea's National Intelligence Service has accused North Korea of compromising the servers of two domestic semiconductor manufacturers and pilfering valuable data, with the intrusions taking place in December 2023 and February 2024.

cybersecurity2 years ago

Protect Your Gmail from Hackers with Extension Deletion

A North Korean cybercriminal group called Kimsuky is using a malicious Chrome extension called AF to steal Gmail emails. The attack starts with a phishing email that urges potential victims to install the extension, which immediately begins stealing the contents of emails from the Gmail account. Kimsuky also uses Google Play’s web-to-phone synchronization feature to infect victims’ phones with Android malware. To protect yourself, never click on suspicious emails or download extensions sent to you in an email. Always have antivirus software installed on all your devices and only download apps from the Google Play Store that have been reviewed and given good ratings.