Blog | G5 Cyber Security

Fancy Bear abuses LoJack security software in targeted attacks

Recently, several LoJack agents were found to be connecting to servers that are believed to be controlled by the notorious Russia-linked Fancy Bear APT group. Experts believe nation-state hackers have installed a backdoor in certain copies of LoJack to use it as a surveillance tool, likely as a part of a cyber espionage campaign. The abuse of such kind of software for cyber espionage is very dangerous and insidious, common anti-malware products and security applications whitelist them. At the time of writing, the initial attack vector is still unclear.”]

Source: https://securityaffairs.co/wordpress/72072/intelligence/fancy-bear-abuses-lojack.html

Exit mobile version