Baddies hijack Korean ERP vendor's update systems to spew malware
ID: a251cd11-c5bf-5560-b4ee-64225577746b
STIX ID: report--a251cd11-c5bf-5560-b4ee-64225577746b
Feed Name: The Register (Security)
AhnLab reports that a South Korean ERP vendor's product update server was compromised to deliver a backdoor named Xctdoor via a modified ClientUpdater.exe which executes a DLL using Regsvr32. The activity is linked to Andariel (a Lazarus-affiliated group) and the malware can exfiltrate system information, execute remote commands, capture screenshots, log keystrokes and clipboard data. The intrusion represents a supply-chain style attack affecting ERP update infrastructure and targeted sectors include defense and other organizations; AhnLab urges heightened monitoring and patching of asset management programs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
