Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware
ID: 37cb68ac-fa9b-52e8-84a7-8029820d7000
STIX ID: report--37cb68ac-fa9b-52e8-84a7-8029820d7000
Feed Name: The Hacker News
Threat Score
North Korean-linked APT Kimsuky has been observed exploiting ConnectWise ScreenConnect flaws (CVE-2024-1708/1709) to deploy a new VB-based malware called TODDLERSHARK—an evolution of BabyShark/ReconShark—that uses mshta execution, scheduled-task persistence, polymorphic tricks, and C2-based data exfiltration; the activity includes targeted intrusions against semiconductor firms and demonstrates active, high-risk exploitation by a nation-state actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
