North Korea Hits ScreenConnect Bugs to Drop 'ToddleShark' Malware
ID: 27ef9cfe-aa90-597a-a1df-a02a417b38ef
STIX ID: report--27ef9cfe-aa90-597a-a1df-a02a417b38ef
Feed Name: Dark Reading
Threat Score
North Korean APT Kimsuky is actively exploiting critical ConnectWise ScreenConnect vulnerabilities (notably CVE-2024-1709) to deploy a new polymorphic backdoor called ToddleShark that uses randomized code, MSHTA execution, and PEM-protected C2 to evade detection; vendors and customers are urged to apply patches to on-prem ScreenConnect instances immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
