Get a Pentest and security assessment of your IT network.

News

Lazarus APT conceals malicious code within BMP image to drop its RAT

The North Korean APT uses a clever technique to bypass security products by embedding one of its payload as a BMP image. The attack likely started by distributing phishing emails that were weaponized with a malicious document. The document creation time is 31 March 2021 which indicates that the attack happened around the same time. This is because the document contains a PNG image that has a compressed zlib malicious object and since its compressed it can not be detected by static detections. Then the threat actor just used a simple conversion mechanism to decompress the malicious content.”]

Source: https://blog.malwarebytes.com/threat-intelligence/2021/04/lazarus-apt-conceals-malicious-code-within-bmp-file-to-drop-its-rat/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months