BTC $65266.0064
ETH $3170.2759
BNB $579.9567
SOL $151.5810
stETH $3170.3792
XRP $0.5307
DOGE $0.1622
TON $6.2152
ADA $0.5047
AVAX $37.5087
wstETH $3690.1011
WBTC $65350.8728
DOT $7.1858
WETH $3168.2550
TRX $0.1112
BCH $512.3933
LINK $14.9136
MATIC $0.7262
ICP $15.2978
UNI $7.8248
LTC $85.1449
DAI $1.0008
RNDR $9.1190
CAKE $2.9399
IMX $2.1935
STX $2.8650
ETC $27.9082
FDUSD $0.9998
MNT $1.2003
NEAR $6.3271
FIL $6.6129
OKB $55.7832
HBAR $0.0909
TAO $475.1056
VET $0.0423
WIF $3.0785
ATOM $8.6865
MKR $3070.6157
KAS $0.1185
FET $2.4759
GRT $0.2860
INJ $29.1371
PEPE $0.0000
USDE $0.9998
XLM $0.1150
THETA $2.2569
XMR $121.6010
BTC $65266.0064
ETH $3170.2759
BNB $579.9567
SOL $151.5810
stETH $3170.3792
XRP $0.5307
DOGE $0.1622
TON $6.2152
ADA $0.5047
AVAX $37.5087
wstETH $3690.1011
WBTC $65350.8728
DOT $7.1858
WETH $3168.2550
TRX $0.1112
BCH $512.3933
LINK $14.9136
MATIC $0.7262
ICP $15.2978
UNI $7.8248
LTC $85.1449
DAI $1.0008
RNDR $9.1190
CAKE $2.9399
IMX $2.1935
STX $2.8650
ETC $27.9082
FDUSD $0.9998
MNT $1.2003
NEAR $6.3271
FIL $6.6129
OKB $55.7832
HBAR $0.0909
TAO $475.1056
VET $0.0423
WIF $3.0785
ATOM $8.6865
MKR $3070.6157
KAS $0.1185
FET $2.4759
GRT $0.2860
INJ $29.1371
PEPE $0.0000
USDE $0.9998
XLM $0.1150
THETA $2.2569
XMR $121.6010
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Worok hackers spy on officials through pictures


    If you are a civil servant from Mexico, be careful when someone sends you a meme.

    Researchers from the information security company Avast said that the recently discovered Worok group is distributing stego-malware in order to quietly steal confidential data.

    Hackers use DLL Side-Loading technology when gaining initial access to install CLRLoad malware, which then launches PNGLoader. CLRLoader is a DLL file that uses the DllMain method to load the next stage, the .NET variant of PNGLoader.

    PNGLoader is a loader that extracts bytes from a PNG file and reverse engineer them into executable code. PNGLoader is a .NET based DLL obfuscated with .NET Reactor. The file description imitates the description of legitimate software. In our case, the PNG files were located in the C:\Program Files\Internet Explorer folder, so the image does not attract attention.

    This new malware, codenamed "DropboxControl", is an information stealing implant that uses the Dropbox account for command and control, allowing the hacker to upload and download files to specific folders and execute commands present on a specific file.

    Some of the commands allow:

    run arbitrary executable files;
    upload and download data;
    delete and rename files;
    collect information about files;
    analyze network connections;
    remove system metadata.

    DropboxControl has already affected companies and government agencies in Cambodia, Vietnam, Mexico, and other countries, according to Avast. The deployment of DropboxControl as a tool to collect certain files and data of interest to attackers clearly points to the spying nature of Worok's campaigns.

    Author DeepWeb
    New BatLoader malware: continuation of old campaigns or creation of a new virus?
    US Department of Health warns medical organizations about Venus ransomware

    Comments 0

    Add comment