Based on reporting from SecurityScorecard’s STRIKE team, the North Korean state-backed threat actor employs a React and Node.js-based system in each C2 server to enable centralized management of stolen data, observation of compromised hosts, and payload distribution.
Related Posts
RansomHub takes responsibility for Texas city, Minneapolis agency breaches
Both Texas’ City of Coppell and the Minneapolis Park and Recreation Board were admitted to have been compromised by the…
Additional Pegasus spyware-hit devices identified
New infections of NSO Group’s Pegasus spyware have been discovered by mobile threat hunting firm iVerify across seven of 2,500…
Purported Cleo hack victimization refuted by some firms
While major German manufacturer Covestro confirmed having its U.S. logistics server’s data impacted by the Clop hack, leading U.S. car…