North Korea Hackers Using New “Dolphin” Backdoor to Spy on South Korean Targets

Teilen:

The North Korea-linked ScarCruft group has been attributed to a previously undocumented backdoor called Dolphin that the threat actor has used against targets located in its southern counterpart.

“The backdoor […] has a wide range of spying capabilities, including monitoring drives and portable devices and exfiltrating files of interest, keylogging and taking screenshots, and stealing credentials from browsers,” ESET researcher Filip Jurčacko sagte in a new report published today.

Dolphin is said to be selectively deployed, with the malware using cloud services like Google Drive for data exfiltration as well as command-and-control.

The Slovak cybersecurity company said it found the implant deployed as a final-stage payload as part of a watering hole attack in early 2021 directed against a South Korean digital newspaper.

The campaign, first uncovered by Kaspersky und Volexity last year, entailed the weaponization of two Internet Explorer flaws (CVE-2020-1380 und CVE-2021-26411) to drop a backdoor named BLUELIGHT.

ScarCruft, also called APT37, InkySquid, Reaper, and Ricochet Chollima, is a geo-political motivated APT group that has a track record of attacking government entities, diplomats, and news organizations associated with North Korean affairs. It’s been known to be active since at least 2012.

Bild41 1

Earlier this April, cybersecurity firm Stairwell disclosed details of a spear-phishing attack targeting journalists covering the country with the ultimate goal of deploying a malware dubbed GOLDBACKDOOR that shares tactical overlaps with BLUELIGHT.

The latest findings from ESET shed light on a second, more sophisticated backdoor delivered to a small pool of victims via BLUELIGHT, indicative of a highly-targeted espionage operation.

This, in turn, is achieved by executing an installer shellcode that activates a loader comprising a Python and shellcode component, the latter of which runs another shellcode loader to drop the backdoor.

“While the BLUELIGHT backdoor performs basic reconnaissance and evaluation of the compromised machine after exploitation, Dolphin is more sophisticated and manually deployed only against selected victims,” Jurčacko explained.

What makes Dolphin a lot more potent than BLUELIGHT is its ability to search removable devices and connected smartphones, and exfiltrate files of interest, such as media, documents, emails, and certificates.

The backdoor, since its original discovery in April 2021, is said to have undergone three successive iterations that come with its own set of feature improvements and grant it more detection evasion capabilities.

“Dolphin is another addition to ScarCruft’s extensive arsenal of backdoors abusing cloud storage services,” Jurčacko said. “One unusual capability found in prior versions of the backdoor is the ability to modify the settings of victims’ Google and Gmail accounts to lower their security, presumably in order to maintain account access for the threat actors.”

https://thehackernews.com/2022/12/north-korea-hackers-using-new-dolphin.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:23 am, Juni 1, 2025
Wetter-Symbol 15°C
L: 14° | H: 16°
klarer Himmel
Luftfeuchtigkeit: 77 %
Druck: 1014 mb
Wind: 15 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 16°°C 0.2 mm 20% 15 mph 79 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 7 mph 79 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 77 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 46 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 37 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,046.40
0.39%
Ethereum(ETH)
€2,223.25
-0.02%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.91
1.82%
Solana(SOL)
€137.51
0.03%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.168698
-0.24%
Shiba Inu(SHIB)
€0.000011
1.61%
Pepe(PEPE)
€0.000011
1.64%
Peanut das Eichhörnchen(PNUT)
€0.229867
6.16%
Nach oben scrollen