Worok new cyberespionage group

ESET researchers uncovered a previously unknown cyberespionage group they named Worok. The Worok group has attacked various "high-profile" public and private sector organizations in industries such as telecommunications, finance, shipping, energy, and defense. The targets are mainly in Asia, the Middle East and Africa.

To attack their targets, the Worok team develops its own cyberespionage tools, while also leveraging existing ones. So the team has used ProxyShell vulnerabilities to get initial σε ορισμένες περιπτώσεις, ενώ το backdoor PowHeartBeat που it has various capabilities, including running commands/processes and uploading and downloading files.

According to ESET telemetry, the Worok group has been active since at least 2020 and continues to be active today.

"We have reasonable suspicions that its administrators y software companies seek to extract information from their victims and this is because they focus on high-profile companies in Asia and Africa, focusing on public and private organizations, with a particular emphasis on government bodies," says ESET researcher Thibaut Passilly who identified the Worok group .

In late 2020, Worok targeted governments and companies in several countries. From May 2021 to January 2022, she took a hiatus from her activities, but in February 2022 she returned making :

• To an energy company in Central Asia and
• In a public sector enterprise in Southeast Asia

"Although the information we have at this stage is limited, we hope that the publicity given to this group will encourage other researchers to share information," adds Passilly.

For more technical information about the Worok team, see the blogpost “Worok: The big picture”At WeLiveSecurity.

Illustration of Worok's target areas and sectors

work

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.
Worok, spies, iguru

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).