BTC $102555.0987
ETH $2456.9606
XRP $2.1324
BNB $641.9801
SOL $146.8903
TRX $0.2773
DOGE $0.1753
ADA $0.6377
stETH $2452.7861
WBTC $102397.3253
HYPE $34.3728
wstETH $2945.2438
SUI $2.9837
USDS $0.9997
LINK $13.1836
XLM $0.2604
LEO $8.7597
AVAX $19.1380
BCH $384.4793
TON $3.0613
HBAR $0.1631
WETH $2444.3083
LTC $84.3507
weETH $2618.6197
DOT $3.9161
BSC-USD $0.9966
XMR $319.2559
BGB $4.5675
BTCB $102330.9123
WBT $31.0630
USDE $1.0012
PI $0.6232
PEPE $0.0000
AAVE $248.8850
UNI $6.0395
sUSDe $1.1780
DAI $1.0002
TAO $360.3910
OKB $49.9854
CRO $0.0984
APT $4.5773
NEAR $2.3054
CBBTC $102488.4812
ICP $4.9439
ETC $16.5785
ONDO $0.7960
GT $18.6960
BTC $102555.0987
ETH $2456.9606
XRP $2.1324
BNB $641.9801
SOL $146.8903
TRX $0.2773
DOGE $0.1753
ADA $0.6377
stETH $2452.7861
WBTC $102397.3253
HYPE $34.3728
wstETH $2945.2438
SUI $2.9837
USDS $0.9997
LINK $13.1836
XLM $0.2604
LEO $8.7597
AVAX $19.1380
BCH $384.4793
TON $3.0613
HBAR $0.1631
WETH $2444.3083
LTC $84.3507
weETH $2618.6197
DOT $3.9161
BSC-USD $0.9966
XMR $319.2559
BGB $4.5675
BTCB $102330.9123
WBT $31.0630
USDE $1.0012
PI $0.6232
PEPE $0.0000
AAVE $248.8850
UNI $6.0395
sUSDe $1.1780
DAI $1.0002
TAO $360.3910
OKB $49.9854
CRO $0.0984
APT $4.5773
NEAR $2.3054
CBBTC $102488.4812
ICP $4.9439
ETC $16.5785
ONDO $0.7960
GT $18.6960
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Indian defence and government agencies have been hacked by Sidecopy

    Attackers use the well-known flaw in WinRAR to do their damage.

    A new cyberattack was launched by the Indian hacker group Sidecopy, which has been active since 2019. This was reported by experts from the Chinese cybersecurity firm Hunting Shadow Lab. The Indian armed forces, government agencies, and defence establishments are usually the group's targets.

    A single control server linked two hacking chains in the new attack:

    1. using the CVE-2023-38831 flaw in WinRAR to get the AllaKore RAT malware on targets.
    2. attaching harmful files to phishing emails that have already been sent. When the harmful Windows shortcut with the LNK extension is opened, a PDF file that looks like a real document about the work of the Indian organisation AIANGO comes to the fore. The DRAT Trojan is downloaded and started at the same time in the background.

    According to an analysis of the bait files' contents, the attack was once again aimed at the Indian military and defence establishments. Professionals say that the use of the WinRAR flaw points to a new tool in the Sidecopy toolkit. Hacking groups are already actively using this flaw against people.

    After a careful look at the malware used in the attack, the following was found:

    1. This is a normal remote access Trojan called Allakore RAT. It gets into a system through a flaw in WinRAR and can download and upload files as well as gather different kinds of information about it. His connection to the attackers' C2 server was made at 38.242.149.89.
    2. The.NET platform is used to write DRAT, and it is shared through LNK files. It has many features that let it control the system that has been hacked. Its messages are kept secret and encrypted for safety.

    Both programmes used different ways to hide their command and control servers and hide their code. Along with sharing indicators of compromise (IoC), Hunting Shadow Lab has already built rules into its products for finding malware and attacker infrastructure.

    The Sidecopy cyberattack shows how important it is to protect against all threats. Technical experts in an organisation are in charge of making sure that old software is updated on time. For example, WinRAR should be updated to version 6.23. They should also make sure that security tools are set up correctly and that systems they are in charge of are regularly scanned for viruses. Users should be careful and not open files that look sketchy that come from unknown sources.

    Author reign3d
    A new cyber threat poses a data theft risk to Chinese government agencies
    The hacker group Cyber Av3ngers says they broke into garbage treatment plants in ten cities

    Comments 0

    Add comment