Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

More than 70 organizations in several sectors aimed at Chinese Cyber ​​Spying Group

June 9, 2025

Two different botnets exploit the vulnerability of the WAZUH server to launch attacks based on peaceful

June 9, 2025

Think what your IDP or CASB covers the shadow? These 5 risks prove differently

June 9, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » New cyber threat targets Azerbaijani and Israeli diplomats, stealing sensitive data
Global Security

New cyber threat targets Azerbaijani and Israeli diplomats, stealing sensitive data

AdminBy AdminAugust 15, 2024No Comments2 Mins Read
Azerbaijan and Israel Diplomats
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


August 15, 2024Ravi LakshmananCyber ​​espionage / data theft

Azerbaijani and Israeli diplomats

A previously unknown threat actor was attributed to a series of attacks on Azerbaijan and Israel to steal sensitive data.

The attack campaign, discovered by NSFOCUS on July 1, 2024, used phishing emails to target Azerbaijani and Israeli diplomats. Activity is tracked under a pseudonym Actor 240524.

“Actor240524 has the ability to steal secrets and modify file data using various countermeasures to avoid over-disclosure of attack tactics and methods,” the cybersecurity company said. said in an analysis published last week.

Cyber ​​security

Attack chains begin by using phishing emails containing Microsoft Word documents that, when opened, prompt recipients to “Enable content” and run a malicious macro responsible for executing an intermediate loader payload codenamed ABCloader (“MicrosoftWordUpdater.log”).

In the next step, ABCloader acts as a conduit to decrypt and download a malicious DLL called ABCsync (“synchronize.dll”), which then communicates with a remote server (“185.23.253(.)143”) to receive and execute a command.

Azerbaijani and Israeli diplomats

“Its primary function is to detect the running environment, decode the program, and load the next DLL (ABCsync),” NSFOCUS said. “It then performs various anti-sandboxing and anti-analysis techniques to detect the environment.”

Some of the prominent features of ABCsync are executing remote shells, executing commands using cmd.exe, and extracting system information and other data.

ABCloader and ABCsync were observed to use techniques such as string encryption to mask important file paths, file names, keys, error messages, and command and control addresses (C2). They also perform several checks to determine if processes are being debugged or running in a virtual machine or sandbox by checking the display resolution.

Cyber ​​security

Another important step taken by Actor240524 is that it checks if there are less than 200 running processes in the compromised system and if so, it exits the malicious process.

ABCloader is also designed to run a similar loader called “synchronize.exe” and a DLL called “vcruntime190.dll” or “vcruntime220.dll” that are capable of configuring persistence on the host.

“Azerbaijan and Israel are allied countries with close economic and political exchanges,” NSFOCUS said. “Operation Actor240524 this time likely targets the cooperative relationship between the two countries, targeting phishing attacks on diplomatic personnel of both countries.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

More than 70 organizations in several sectors aimed at Chinese Cyber ​​Spying Group

June 9, 2025

Two different botnets exploit the vulnerability of the WAZUH server to launch attacks based on peaceful

June 9, 2025

Think what your IDP or CASB covers the shadow? These 5 risks prove differently

June 9, 2025

Openai prohibits chatgpt accounts used by Russian, Iranian and Chinese hacking groups

June 9, 2025

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

More than 70 organizations in several sectors aimed at Chinese Cyber ​​Spying Group

June 9, 2025

Two different botnets exploit the vulnerability of the WAZUH server to launch attacks based on peaceful

June 9, 2025

Think what your IDP or CASB covers the shadow? These 5 risks prove differently

June 9, 2025

Openai prohibits chatgpt accounts used by Russian, Iranian and Chinese hacking groups

June 9, 2025

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

More than 70 organizations in several sectors aimed at Chinese Cyber ​​Spying Group

June 9, 2025

Two different botnets exploit the vulnerability of the WAZUH server to launch attacks based on peaceful

June 9, 2025

Think what your IDP or CASB covers the shadow? These 5 risks prove differently

June 9, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.