Cybersecurity researchers have discovered a new wave of cyber attacks by a China-based hacker group called “Sparking Goblin.”
According to a new report published by cyber firm FireEye, the Sparking Goblin hackers have been using a new malware called “LookBack” to attack several organisations in the United States and South Korea.
The Sparkling Goblin advanced persistent threat (APT) group has been active since at least 2012, targeting the Middle East and North African entities with watering hole attacks and spear-phishing campaigns.
In the new campaign, the hackers used a custom-built malware called LookBack to gain initial access to victim networks. Once inside, the attackers use various tools and techniques to move laterally across the web and collect sensitive data.
Now, researchers have uncovered a new campaign attributed to the group that uses malicious Microsoft Word documents exploiting a recently patched flaw in the software to drop a backdoor payload onto the victim’s system.
The researchers dubbed the “FlawedAmmyy” backdoor gives attackers remote access and control over the compromised system. It can also upload and download additional files, execute commands, and take screenshots.
“This campaign is notable for its use of a new variant of FlawedAmmyy, a well-known remote access trojan (RAT) that has been used in previous attacks attributed to the Sparking Goblin APT group,” the researchers said.
“The RAT allows an attacker to take full control of an infected system and perform various actions, such as stealing sensitive information, executing commands, and downloading, uploading files.”
The researchers believe the campaign is still active and advise organisations to patch their systems to prevent exploitation.
This latest campaign is just one example of how hackers use new and old exploits to target businesses and individuals worldwide. It’s essential to stay up-to-date on the latest cybersecurity threats and take steps to protect your devices and data.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...