Lazarus-Hacker nutzen Log4j, um US-Energieunternehmen zu hacken

Teilen:

A new cyber espionage campaign targeting US, Canadian, and Japanese energy providers has been linked to the North Korean state-sponsored Lazarus hacking group, according to security researchers.

Cisco Talos, a threat intelligence company, announced Thursday that Lazarus, also known as APT38, was observed targeting unidentified energy providers in the United States, Canada, and Japan between February and July of this year.

According to Cisco’s findings, the hackers exploited a year-old Log4j vulnerability known as Log4Shell to compromise internet-exposed VMware Horizon servers in order to gain an initial foothold on a victim’s enterprise network before deploying bespoke malware known as “VSingle” and “YamaBot” to gain long-term persistent access.

Japan’s national cyber emergency response team, known as CERT, recently linked YamaBot to the Lazarus APT. Symantec first disclosed information of this espionage campaign in April of this year, attributing the operation to “Stonefly,” another North Korean hacking group with some overlaps with Lazarus.

However, Cisco Talos discovered a previously unknown remote access trojan (RAT) called “MagicRAT,” which is attributed to the Lazarus Group and is used by hackers for reconnaissance and credential theft.

Talos researchers Jung soo An, Asheer Malhotra, and Vitor Ventura, “The main goal of these attacks was likely to establish long-term access into victim networks to conduct espionage operations in support of North Korean government objectives. This activity aligns with historical Lazarus intrusions targeting critical infrastructure and energy companies to establish long-term access to siphon off proprietary intellectual property.”

However, in recent months, the group has shifted its focus to blockchain and cryptocurrency organisations. It has been associated with the recent thefts of $100 million in cryptocurrency from Harmony’s Horizon Bridge and $625 million in cryptocurrency from the Ronin Network, an Ethereum-based sidechain created for the popular play-to-earn game Axie Infinity.

Pyongyang has long used stolen cryptocurrency and information theft to finance its nuclear weapons programme. In July, the United States offered a $10 million reward for data on members of state-sponsored North Korean threat groups, including Lazarus, more than doubling the amount previously offered. The State Department made the announcement in April.

The Lazarus Group is a North Korean-backed hacking organisation best known for the high-profile Sony hack in 2016 and the WannaCry ransomware attack in 2017. Lazarus is also motivated by efforts to support North Korea’s state objectives, such as military R&D and evasion of international sanctions.

https://www.cysecurity.news/2022/09/lazarus-hackers-are-using-log4j-to-hack.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:25 pm, Juli 8, 2025
Wetter-Symbol 17°C
L: 16° | H: 19°
overcast clouds
Luftfeuchtigkeit: 59 %
Druck: 1019 mb
Wind: 2 mph WNW
Windböe: 3 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 90%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:53 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
16° | 19°°C 0.18 mm 18% 7 mph 57 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 17°°C 0 mm 0% 3 mph 56 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 16°°C 0 mm 0% 3 mph 54 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,860.99
0.69%
Ethereum(ETH)
€2,222.10
2.70%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
1.44%
Solana(SOL)
€128.66
1.70%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145616
2.25%
Shiba Inu(SHIB)
€0.000010
2.61%
Pepe(PEPE)
€0.000009
3.53%
Nach oben scrollen