Worok Hackers Target High-Profile Asian Companies and Governments

Teilen:

High-profile companies and local governments located primarily in Asia are the subjects of targeted attacks by a previously undocumented espionage group dubbed Worok that has been active since late 2020.

“Worok’s toolset includes a C++ loader CLRLoad, a PowerShell backdoor PowHeartBeat, and a C# loader PNGLoad that uses steganography to extract hidden malicious payloads from PNG files,” ESET researcher Thibaut Passilly sagte in a new report published today.

Worok is said to share overlaps in tools and interests with another adversarial collective tracked as TA428, with the group linked to attacks against entities spanning energy, financial, maritime, and telecom sectors in Asia as well as a government agency in the Middle East and a private firm in southern Africa.

Malicious activities undertaken by the group experienced a noticeable break from May 2021 to January 2022, before resuming the next month. The Slovak cybersecurity firm assessed the group’s goals to be aligned with information theft.

Initial foothold to target networks through 2021 and 2022 entailed the use of ProxyShell exploits in select instances, followed by deploying additional custom backdoors for entrenched access. Other initial compromise routes are unknown as yet.

Cyberespionage

Among the tools in Worok’s malware arsenal is a first-stage loader called CLRLoad, which is succeeded by a .NET-based steganographic loader codenamed PNGLoad that’s capable of executing an unknown PowerShell script embedded in a PNG image file.

Infection chains in 2022 have since dropped CLRLoad in favor of a full-featured PowerShell implant referred to as PowHeartBeat that’s subsequently used to launch PNGLoad, in addition to communicating with a remote server via HTTP or ICMP to execute arbitrary commands, send and receive files, and carry out related file operations.

ESET said it was unable to retrieve any of the final-stage PNG payloads, although it’s suspected that the malware could be concealed in valid, innocuous-looking PNG images and therefore “hide in plain sight” without attracting attention.

“Worok is a cyber espionage group that develops its own tools, as well as leveraging existing tools, to compromise its targets,” Passilly said.

“Stealing information from their victims is what we believe the operators are after because they focus on high-profile entities in Asia and Africa, targeting various sectors, both private and public, but with a specific emphasis on government entities.”

 

Found this article interesting? Follow THN on FacebookTwitter  und LinkedIn to read more exclusive content we post.
Quelle 06092022 1951 https://thehackernews.com/2022/09/worok-hackers-target-high-profile-asian.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:43 am, Juni 1, 2025
Wetter-Symbol 14°C
L: 12° | H: 15°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1014 mb
Wind: 3 mph WSW
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 15°°C 0.2 mm 20% 15 mph 81 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 7 mph 81 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 80 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 17°°C 0 mm 0% 11 mph 57 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 37 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,814.63
0.45%
Ethereum(ETH)
€2,209.41
-0.03%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.90
1.29%
Solana(SOL)
€136.36
0.18%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167109
-0.86%
Shiba Inu(SHIB)
€0.000011
1.50%
Pepe(PEPE)
€0.000011
1.93%
Peanut das Eichhörnchen(PNUT)
€0.227786
4.52%
Nach oben scrollen