Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » APT-K-47 uses Hajj-themed decoys to deliver Advanced Asyncshell malware
Global Security

APT-K-47 uses Hajj-themed decoys to deliver Advanced Asyncshell malware

AdminBy AdminNovember 22, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 22, 2024Ravi LakshmananCyber ​​attack / malware

A threat actor known as The mysterious elephant observed the use of an advanced version of the malware called Asynshell.

The attack campaign is said to have used Hajj-themed decoys to trick victims into executing a malicious payload disguised as a Microsoft Compiled HTML Help (CHM) file, Knownsec 404 command said in an analysis published today.

Mysterious Elephant, which is also known as APT-K-47, is a threat actor of South Asian origin that has been active since at least 2022, primarily against Pakistani organizations.

Cyber ​​security

The group’s tactics and tools were found to share similarities with those of other threat actors operating in the region, such as SideWinder, Confucius, and Bitter.

In October 2023, the group was connected to a phishing campaign that deployed a backdoor called ORPCBackdoor as part of attacks targeting Pakistan and other countries.

The exact initial access vector used by Mysterious Elephant in the latest campaign is unknown, but it likely involved the use of phishing emails. The method leads to the delivery of a ZIP archive containing two files: a CHM file that claims to be about the 2024 Hajj policy, and a hidden executable.

When CHM starts, it is used to display the decoy document, a legal pdf file hosted on the website of the Government of Pakistan for Religious Affairs and Interfaith Harmony, while the binary executes inconspicuously in the background.

A relatively simple malware designed to install a shell cmd with a remote server, with the Knownsec 404 identifying functional matches with Asyncshell, another tool the threat has repeatedly used since mid-2023.

To date, four different versions of Asyncshell have been discovered that boast cmd and PowerShell command execution capabilities. The initial attack chains that spread the malware were found to exploit a security flaw in WinRAR (CVE-2023-38831CVSS score: 7.8) to cause infection.

Cyber ​​security

Additionally, subsequent iterations of the malware have moved from using TCP to HTTPS for command-and-control (C2) communication, not to mention using an updated attack sequence that uses a Visual Basic script to display a decoy document and launch its scheduled job tool.

“APT-K-47 is seen to frequently use Asyncshell to launch its attack since 2023 and has gradually upgraded its attack chain and payload code,” the Knownsec 404 team said.

“In recent attacks, this group cleverly used masked service requests to control the final address of the shell server, changing the fixed C2 of previous versions to a variable C2, which shows the importance of APT-k-47’s internal organization locations in Asyncshell. “

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.