#1 Trending Cybersecurity News & Magazine
Sunday, October 1, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Cyber Security Legal Challenges

    Navigating The Post-Incident Cybersecurity Legal Challenges

    Cybersecurity Budget Trends 2023

    Cybersecurity Budgets Trends in 2023 Record a Meagre 6% Rise

    Cybersecurity Awareness

    Remote Workers Outshine In-Office Counterparts in Cybersecurity Awareness

    Cybersecurity Awareness Month

    Cybersecurity Awareness Month: 20 Years of Protecting Our Digital Future

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    Phishing HTML Files

    Evading Antivirus: The Rise of Phishing HTML Files

    Indian Taxpayer Data Leak

    Indian Taxpayer Data Leak: Login Credentials Exposed on Hacker Forum

    NoName Ransomware Group

    NoName Ransomware Group Targets Transport Organizations in the UK

    Largest Healthcare Data Breach

    McLaren Healthcare: Largest Healthcare Data Breach by ALPHV, 6TB Data Stolen

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Cyber Security Legal Challenges

    Navigating The Post-Incident Cybersecurity Legal Challenges

    Cybersecurity Budget Trends 2023

    Cybersecurity Budgets Trends in 2023 Record a Meagre 6% Rise

    Cybersecurity Awareness

    Remote Workers Outshine In-Office Counterparts in Cybersecurity Awareness

    Cybersecurity Awareness Month

    Cybersecurity Awareness Month: 20 Years of Protecting Our Digital Future

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    Phishing HTML Files

    Evading Antivirus: The Rise of Phishing HTML Files

    Indian Taxpayer Data Leak

    Indian Taxpayer Data Leak: Login Credentials Exposed on Hacker Forum

    NoName Ransomware Group

    NoName Ransomware Group Targets Transport Organizations in the UK

    Largest Healthcare Data Breach

    McLaren Healthcare: Largest Healthcare Data Breach by ALPHV, 6TB Data Stolen

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cybersecurity News

Researchers Attribute Lazarus APT Group with Backdoor Payload WinorDLL64

Researchers discovered overlaps in behavior and code with Lazarus samples from Operation GhostSecret and the Bankshot implant described by McAfee.

Ashish Khaitan by Ashish Khaitan
March 1, 2023 - Updated on March 24, 2023
in Cybersecurity News, Firewall Daily
0
Lazarus APT Group with Backdoor Payload WinorDLL64
619
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

Researchers have discovered a backdoor payload WinorDLL64, which can acquire extensive system information, manipulate files, and execute additional commands. They attribute it to the North Korea-aligned advanced persistent threat (APT) group Lazarus.

WinorDLL64 communicates over a connection already established by the Wslink loader, and the initial Wslink compromise vector has yet to be identified.

You might also like

Navigating The Post-Incident Cybersecurity Legal Challenges

Cybersecurity Budgets Trends in 2023 Record a Meagre 6% Rise

Remote Workers Outshine In-Office Counterparts in Cybersecurity Awareness

Although no data had suggested, Wslink was a tool from a known threat actor, an extensive analysis of the payload has led researchers at ESET to attribute WinorDLL64 to the Lazarus APT group with low confidence based on the targeted region and overlap in both behavior and code with known Lazarus samples.

Also known as HIDDEN COBRA, the Lazarus group has been active since 2009. This group has been responsible for high-profile incidents, including the WannaCry outbreak, tens-of-millions-of-dollar cyber heist, and the Sony Pictures Entertainment hack.

Relationship between Lazarus and WinorDLL64 

ESET researchers discovered overlaps in behavior and code with Lazarus samples from Operation GhostSecret and the Bankshot implant described by McAfee.

Their analysis used the FE887FCAB66D7D7F79F05E0266C0649F0114BA7C sample from GhostSecret to compare against WinorDLL64 (1BA443FDE984CEE85EBD4D4FA7EB1263A6F1257F) unless specified otherwise.

According to ESET researchers, the Lazarus APT group is systematically organized, well-prepared, and comprises several subgroups that use a large toolset.

The discovery of WinorDLL64 highlights the sophistication of their operations. It emphasizes the need for organizations to remain vigilant and take necessary precautions to protect their systems and networks from cyber threats.

Organizations must invest in advanced threat detection and response capabilities, keep their software and security solutions up to date, regularly backup critical data, implement best practices, and educate employees on cybersecurity hygiene to avoid such advanced threats. 

Technical analysis of the sample 

According to a recent report, the latest GhostSecret sample reported by McAfee dates back to February 2018. However, the first sample of Wslink was discovered in late 2018, and fellow researchers reported hits in August of the same year, which they disclosed after ESET’s publication.

This indicates that these samples were detected within a relatively short period of time.

ESET researchers also found that the PE-rich headers in the Wslink and Lazarus samples indicate the same development environment.

Projects of similar size were used in several other known Lazarus samples, such as 70DE783E5D48C6FBB576BC494BAF0634BC304FD6 and 8EC9219303953396E1CB7105CDB18ED6C568E962. This overlap was found using specific rules that cover only these Wslink and Lazarus samples, an indicator with low weight. 

This report highlights the continued threat the Lazarus APT group poses and their targeting of organizations worldwide.

As a result, organizations must remain vigilant and take necessary precautions to protect their systems and networks from cyber threats.

This includes regularly updating all software and security solutions, backing up critical data, implementing best practices, and educating employees about the importance of cybersecurity hygiene.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Backdoor Payload WinorDLL64Lazarus APT group
Previous Post

Top 10 Dark Web Monitoring Tools To Check Out In 2023

Next Post

Mayday! Nok Air Faces Another Ransomware Attack, This Time LockBit

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

Cyber Security Legal Challenges
Cybersecurity News

Navigating The Post-Incident Cybersecurity Legal Challenges

by Ishita Tripathi
October 1, 2023
Cybersecurity Budget Trends 2023
Firewall Daily

Cybersecurity Budgets Trends in 2023 Record a Meagre 6% Rise

by Ishita Tripathi
October 1, 2023
Cybersecurity Awareness
Firewall Daily

Remote Workers Outshine In-Office Counterparts in Cybersecurity Awareness

by Ishita Tripathi
September 30, 2023
Cybersecurity Awareness Month
Cybersecurity Awareness Month

Cybersecurity Awareness Month: 20 Years of Protecting Our Digital Future

by Ishita Tripathi
September 30, 2023
Facial Recognition Ban
Firewall Daily

New York State Education Department Bans Facial Recognition Scans in Schools

by Vishwa Pandagle
September 29, 2023
Next Post
Nok Air

Mayday! Nok Air Faces Another Ransomware Attack, This Time LockBit

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

Cyber Security Legal Challenges
Cybersecurity News

Navigating The Post-Incident Cybersecurity Legal Challenges

October 1, 2023
Cybersecurity Budget Trends 2023
Firewall Daily

Cybersecurity Budgets Trends in 2023 Record a Meagre 6% Rise

October 1, 2023
Cybersecurity Awareness
Firewall Daily

Remote Workers Outshine In-Office Counterparts in Cybersecurity Awareness

September 30, 2023
Cybersecurity Awareness Month
Cybersecurity Awareness Month

Cybersecurity Awareness Month: 20 Years of Protecting Our Digital Future

September 30, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance