Eine russische Malware-Gruppe, die bisher eigentlich nur durch Angriffe auf Ziele in der Ukraine auffiel, hat einen USB-Wurm losgelassen, der sich inzwischen weltweit ausbreitet. Der Schädling ist inzwischen unter der Bezeichnung LitterDrifter analysiert worden.
Introduction Gamaredon, also known as Primitive Bear, ACTINIUM, and Shuckworm, is a unique player in the Russian espionage ecosystem that targets a wide variety of almost exclusively Ukrainian entities. While researchers often struggle to uncover evidence of Russian espionage activities, Gamaredon is notably conspicuous. The group behind it conducts large-scale campaigns while still primarily focusing […]
Eine russische Malware-Gruppe, die bisher eigentlich nur durch Angriffe auf Ziele in der Ukraine auffiel, hat einen USB-Wurm losgelassen, der sich inzwischen weltweit ausbreitet. Der Schädling ist inzwischen unter der Bezeichnung LitterDrifter analysiert worden.
`Unlike viruses, worms typically spread through systems on their own. Because of this, it was only a matter of time before #LitterDrifter started operating outside its intended target — whether this was intentional or not, we'll never truly know. `
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
The attack chain involves phishing emails directing victims to a crafted ZIP file exploiting the WinRAR flaw to retrieve a PowerShell script from a remote server on Ngrok.
#Cybersecurity #Russia #Malware #Worm #Ukraine #LitterDrifter #HackerGroup