• News/
  • https://www.bleepingcomputer.com/news/security/screenconnect-flaws-exploited-to-drop-new-toddleshark-malware/

ScreenConnect flaws exploited to drop new ToddleShark malware

BleepingComputer
·
Bill Toulas
·
Published Mar 4, 2024
·
Updated

The North Korean APT hacking group Kimsuky is exploiting ScreenConnect flaws, particularly CVE-2024-1708 and CVE-2024-1709, to infect targets with a new malware variant dubbed ToddleShark. Kimsuky (aka Thallium and Velvet Chollima) is a North Korean state-sponsored hacking group known for cyber espionage attacks on organizations and governments worldwide. The threat actors are exploiting authentication bypass and remote code execution flaws disclosed on February 20, 2024, when ConnectWise urged ScreenConnect customers to immediately upgrade their servers to version 23.9.8 or later. Public exploits for the two flaws were released the next day, and hackers, including ransomware actors, quickly began leveraging them in actual attacks. According to an upcoming report by Kroll's cyber-intelligence team shared with BleepingComputer, the new Kimsuky malware, which exhibits polymorphic traits, appears to have been designed for long-term espionage and intelligence gathering. ToddleShark uses legitimate Microsoft binaries to minimize its trace, performs registry modifications to lower security defenses, and establishes persistent access through scheduled tasks, followed by a phase of continual data theft and exfiltration. Kroll's analysts estimate that ToddleShark is a new variant of Kimsuky's BabyShark and ReconShark backdoors, previously seen targeting government organizations, research centers, universities, and think tanks in the United States, Europe, and Asia. The hackers first ...

Read full article

Affected Software

1 affected component
ConnectWise ScreenConnect
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of vulnerabilities in ScreenConnect by the North Korean hacking group Kimsuky to deliver the ToddleShark malware.

2

What vulnerabilities are being exploited in ScreenConnect?

The vulnerabilities CVE-2024-1708 and CVE-2024-1709 in ScreenConnect are being exploited.

3

Who is behind the ToddleShark malware?

The ToddleShark malware is attributed to the North Korean APT group Kimsuky.

4

What security implications are highlighted in the article?

The exploitation of ScreenConnect vulnerabilities poses significant security risks, allowing malware deployment on targeted systems.

5

What software product is primarily affected by these vulnerabilities?

The primary affected software product is ConnectWise ScreenConnect.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203