logo

North Korea Hits ScreenConnect Bugs to Drop 'ToddleShark' Malware

ID: 27ef9cfe-aa90-597a-a1df-a02a417b38ef

STIX ID: report--27ef9cfe-aa90-597a-a1df-a02a417b38ef

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-03-05

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

North Korean APT Kimsuky is actively exploiting critical ConnectWise ScreenConnect vulnerabilities (notably CVE-2024-1709) to deploy a new polymorphic backdoor called ToddleShark that uses randomized code, MSHTA execution, and PEM-protected C2 to evade detection; vendors and customers are urged to apply patches to on-prem ScreenConnect instances immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.