logo

Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware

ID: 37cb68ac-fa9b-52e8-84a7-8029820d7000

STIX ID: report--37cb68ac-fa9b-52e8-84a7-8029820d7000

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

North Korean-linked APT Kimsuky has been observed exploiting ConnectWise ScreenConnect flaws (CVE-2024-1708/1709) to deploy a new VB-based malware called TODDLERSHARK—an evolution of BabyShark/ReconShark—that uses mshta execution, scheduled-task persistence, polymorphic tricks, and C2-based data exfiltration; the activity includes targeted intrusions against semiconductor firms and demonstrates active, high-risk exploitation by a nation-state actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.