Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Magnet Goblin hacker group exploits 1-day vulnerability to deploy Nerbian RAT
    Cyber Security

    Magnet Goblin hacker group exploits 1-day vulnerability to deploy Nerbian RAT

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 11, 2024Editorial DepartmentZero-day/Endpoint Security

    Magnetic Goblin Hacker Group

    Financially motivated threat actors are called magnet leprechaun are rapidly incorporating one-day security vulnerabilities into their arsenal to exploit them to compromise edge devices and public-facing services and deploy malware on compromised hosts.

    “Threat group Magnet Goblin is characterized by its ability to quickly exploit newly disclosed vulnerabilities, particularly against public-facing servers and edge devices,” Check Point said.

    “In some cases, exploits were deployed within 1 day after they occurred. [proof-of-concept] Following publication, the threat level posed by this actor increased significantly. “

    Internet security

    The adversary’s attacks leveraged unpatched Ivanti Connect Secure VPN, Magento, Qlik Sense, and possibly Apache ActiveMQ servers as initial infection vectors to gain unauthorized access. The group is said to have been active since at least January 2022.

    After successfully exploiting this vulnerability, a cross-platform remote access Trojan (RAT) called Nerbian RAT will be deployed. This Trojan was first disclosed by Proofpoint in May 2022, and its simplified variant is MiniNerbian. Darktrace has previously highlighted the use of the Linux version of the Nerbian RAT.

    1 day vulnerability

    Both viruses allow the execution of arbitrary commands received from a command and control (C2) server and leak the results passed back to it.

    Some other tools used by Magnet Goblin include the WARPWIRE JavaScript credential stealer, the Go-based tunneling software Ligolo, and legitimate remote desktop products such as AnyDesk and ScreenConnect.

    Internet security

    “Magnet Goblin’s activities appear to be financially motivated, quickly exploiting 1-day vulnerabilities to spread their custom Linux malware, Nerbian RAT and MiniNerbian,” the company said.

    “These tools operate under the radar because they mostly reside on edge devices. This is part of an ongoing trend of threat actors targeting hitherto unprotected areas.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.