October 23, 2023
2 mins read

Vietnam-based hackers target India, US, UK

DarkGate is a Remote Access Trojan (RAT) that first emerged in cyberspace in 2018. It is usually offered as a Malware-as-a-Service tool to cybercriminals…reports Asian Lite News

Vietnam-based cybercrime groups are targeting digital marketing firms based in India, the US and the UK by hijacking Facebook business accounts in a malicious campaign, a new report has found.

According to the cybersecurity company WithSecure, the popular malware ‘Darkgate’ has been combined with a Malware as a Service (MaaS) toolkit to infect victims with rival remote access trojans (RATs) and additional information-stealing malware like Ducktail, Lobshot, and Redline.

Multiple infection attempts with DarkGate malware were identified by researchers, targeting these countries on August 4. The lure documents, target patterns, themes, delivery methods, and overall attack tactics are similar to those seen in recent DuckTail infostealer campaigns, the report said.

DarkGate is a Remote Access Trojan (RAT) that first emerged in cyberspace in 2018. It is usually offered as a Malware-as-a-Service tool to cybercriminals.

The researchers examined open-source data associated with the DarkGate malware campaign and discovered connections to multiple infostealers. This pattern indicates that these attacks are being carried out by the same group or threat actor.

“By identifying characteristics of DarkGate malware lures and campaigns, we have been able to find multiple pivot points which lead to other information stealers and malware being used in very similar if not identical campaigns, and it is assessed as likely that the same threat actor group performs these campaigns,” the researchers said.

According to the report, the attack began with a file called ‘Salary and new products.8.4.zip.’ When unwitting users downloaded and extracted it, a VBS script was activated.

This script renamed and duplicated the original Windows binary (Curl.exe) to a new location before connecting to an external server to retrieve two additional files: autoit3.exe and an Autoit3 script compiled.

Following that, the script executed the executable, de-obfuscated, and assembled the DarkGate RAT with the help of strings from the script.

“Based on what we’ve observed, it is very likely that a single actor is behind several of the campaigns we’ve been tracking that target Meta Business accounts,” said senior threat intelligence analyst Stephen Robinson.

After gaining control of an account, the attackers can engage in a variety of malicious activities such as malware distribution and fraud, the report warned.

ALSO READ-India-US 2+2 meeting to be held in Nov second week

Previous Story

X lost over half a billion user visits last month

Next Story

Cyclone Tej Intensifies into Extremely Severe Cyclonic Storm

Previous Story

X lost over half a billion user visits last month

Next Story

Cyclone Tej Intensifies into Extremely Severe Cyclonic Storm

Latest from -Top News

Russian Navy Team Visits Kerala

A six-member Russian Navy delegation visited key Indian naval training establishments in Kerala as New Delhi and Moscow seek closer defence ties…reports Asian Lite News Desk A six-member Russian Navy delegation led

India, Visegrad-4 Reset Opens New European Front

India’s renewed engagement with the Visegrad-4 could strengthen ties with Central and Eastern Europe as the regional grouping seeks a fresh role…reports Asian Lite News Desk The meeting between External Affairs Minister

India, Cyprus Deepen Maritime Cooperation

India and Cyprus have held the first meeting of their Joint Maritime Committee, focusing on maritime cooperation, investment and green shipping…reports Asian Lite News Desk India and Cyprus have held the first

Jaishankar Meets Outgoing Bangladesh Envoy

External Affairs Minister S. Jaishankar met Bangladesh’s outgoing High Commissioner Riaz Hamidullah in New Delhi and appreciated his contribution to bilateral ties…reports Asian Lite News Desk External Affairs Minister S. Jaishankar on

Nepal Plans Period Leave for Women Workers

Nepal has proposed introducing menstrual leave for women civil servants as part of amendments to its federal civil service law….reports Asian Lite News Desk Nepal is considering introducing menstrual leave for women
Go toTop

Don't Miss

India to press IAF into service for oxygen import

The Central government is also planning to press the Indian

Pak senator warns of cold war if India become ‘Sixth Eye’

Pak official warned that if India ultimately joined the Five