Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » New Go-based JaskaGO malware targets Windows and macOS systems
    Cyber Security

    New Go-based JaskaGO malware targets Windows and macOS systems

    techempireBy techempireNo Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportDecember 20, 2023Editorial DepartmentCryptocurrency/Malware

    Go-based JaskaGO malware

    A new Go-based information-stealing malware is called Jaska GO It has become the latest cross-platform threat to penetrate Windows and Apple macOS systems.

    AT&T Alien Labs, which discovered the situation, said the malware “comes with a large number of commands from its command and control (C&C) server.”

    The artifact designed for macOS was first discovered in July 2023 and imitates the installers of legitimate software such as CapCut. Other variants of the malware are disguised as AnyConnect and security tools.

    Once installed, JaskaGO performs a check to determine if it is executing in a virtual machine (VM) environment and, if so, performs a harmless task such as pinging Google or printing a nonce to stay under the radar.

    In other scenarios, JaskaGO continues to collect messages from the victim’s system and establishes a connection to its C&C to receive further instructions, including executing shell commands, enumerating running processes, and downloading additional payloads.

    Internet security

    It can also modify the clipboard to facilitate cryptocurrency theft by replacing wallet addresses and stealing files and data from web browsers.

    “On macOS, JaskaGO uses a multi-step process to establish persistence within the system,” said security researcher Ofer Caspi, outlining its methods of running itself with root privileges, disabling Gatekeeper protection, and creating a custom boot daemon (or boot agent). Function. to ensure it starts automatically when the system starts.

    It is unclear how the malware spreads and whether phishing or malvertising bait is involved. The scale of the event is currently unclear.

    “JaskaGO contributes to the growing trend of malware development using the Go programming language,” Caspi said.

    “Go, also known as Golang, is known for its simplicity, efficiency, and cross-platform functionality. Its ease of use makes it an attractive choice for malware authors looking to create versatile and sophisticated threats.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.