ToddyCat APT Targets ESET Bug to Load Silent Malware
ID: 34619b83-7480-5960-8d00-a0b4d5c45086
STIX ID: report--34619b83-7480-5960-8d00-a0b4d5c45086
Feed Name: Dark Reading
Kaspersky reported that the Chinese-speaking ToddyCat APT exploited a DLL search order hijacking vulnerability in ESET antivirus (CVE-2024-11859) to force the product to load a malicious version.dll delivering the TCESB payload, which can stealthily execute code and disable Windows kernel-level security; the actors also leveraged a vulnerable Dell driver (CVE-2021-36276) for kernel-level activity. ESET patched the issue in January and organizations are advised to monitor for installation of known-vulnerable drivers, unexpected kernel debug symbol loads, and to verify digital signatures of loaded system libraries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
