The North Korean APT hacking group Kimsuky is exploiting ScreenConnect flaws, particularly CVE-2024-1708 and CVE-2024-1709, to infect targets with a new malware variant dubbed ToddleShark. Kimsuky (aka Thallium and Velvet Chollima) is a North Korean state-sponsored hacking group known for cyber espionage attacks on organizations and governments worldwide. The threat actors are exploiting authentication bypass and remote code execution flaws disclosed on February 20, 2024, when ConnectWise urged ScreenConnect customers to immediately upgrade their servers to version 23.9.8 or later. Public exploits for the two flaws were released the next day, and hackers, including ransomware actors, quickly began leveraging them in actual attacks. According to an upcoming report by Kroll's cyber-intelligence team shared with BleepingComputer, the new Kimsuky malware, which exhibits polymorphic traits, appears to have been designed for long-term espionage and intelligence gathering. ToddleShark uses legitimate Microsoft binaries to minimize its trace, performs registry modifications to lower security defenses, and establishes persistent access through scheduled tasks, followed by a phase of continual data theft and exfiltration. Kroll's analysts estimate that ToddleShark is a new variant of Kimsuky's BabyShark and ReconShark backdoors, previously seen targeting government organizations, research centers, universities, and think tanks in the United States, Europe, and Asia. The hackers first ...
ScreenConnect flaws exploited to drop new ToddleShark malware
BleepingComputer
·Bill Toulas
·Published Mar 4, 2024
·Updated
Affected Software
1 affected component
ConnectWise ScreenConnect
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of vulnerabilities in ScreenConnect by the North Korean hacking group Kimsuky to deliver the ToddleShark malware.
2
What vulnerabilities are being exploited in ScreenConnect?
The vulnerabilities CVE-2024-1708 and CVE-2024-1709 in ScreenConnect are being exploited.
3
Who is behind the ToddleShark malware?
The ToddleShark malware is attributed to the North Korean APT group Kimsuky.
4
What security implications are highlighted in the article?
The exploitation of ScreenConnect vulnerabilities poses significant security risks, allowing malware deployment on targeted systems.
5
What software product is primarily affected by these vulnerabilities?
The primary affected software product is ConnectWise ScreenConnect.