Tuesday, February 18, 2025
HomeCyber Security NewsDPRK Hackers Exploit MagicLine4NX Zero-day in Supply Chain Attacks

DPRK Hackers Exploit MagicLine4NX Zero-day in Supply Chain Attacks

Published on

SIEM as a Service

Follow Us on Google News

North Korea, DPRK threat actors, have been reportedly involved in several supply-chain attacks to gain unauthorized access to the intranet of an organization.

One of the software exploited by the DPRK threat actors was the MagicLine4NX security authentication program, which contained a zero-day vulnerability.

This vulnerability allowed initial intrusion into an internet-facing system and moved laterally or gained unauthorized access to information.

The threat actors were using a watering-hole attack for these attacks in which one compromise led to supply-chain infection.

The vulnerability was undisclosed but found to be existing in versions MagicLine4NX 1.0.0.1 ~ 1.0.0.26.

Document
Free Webinar

Live API Attack Simulation Webinar

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked. The session will cover: an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

MagicLine4NX Zero-day

As part of the initial access with the Watering-hole attack, threat actors compromised a media outlet website and deployed a malicious script that runs only when accessed by specific IP ranges. 

Suppose any victim from the particular IP range opens an infected article on the compromised website. In that case, the malicious code is executed due to the vulnerable software that connects the victim’s computer to the Command and Control server (C2), providing remote access to the threat actors.

Attack Flow (Source: NCSC)
Attack Flow (Source: NCSC)

The threat actors were then able to access an internet-connected server from the compromised system and exploit the data synchronization function of the network-linked system for spreading malicious code to business-side servers and stealing sensitive information.

Two C2 servers

The business servers affected with malicious codes had two C2 servers one of them acts as a gateway in the middle, and the other is located on the external internet.

In addition to this, the malicious code was capable of exfiltrating initial beacon data and executing encrypted payloads.

However, the code was not able to move laterally due to the security policy of the solution and was blocked from moving, which prevented several pieces of information from being exposed.

Furthermore, a complete report has been published by NCSC, providing detailed information on the DPRK threat actors and their supply chain attack vectors.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension

SectopRAT, also known as Arechclient2, is a sophisticated Remote Access Trojan (RAT) developed using...

Threat Actors Trojanize Popular Games to Evade Security and Infect Systems

A sophisticated malware campaign was launched by cybercriminals, targeting users through trojanized versions of...

New Research Aims to Strengthen MITRE ATT&CK for Evolving Cyber Threats

A recent study by researchers from the National University of Singapore and NCS Cyber...

New LLM Vulnerability Exposes AI Models Like ChatGPT to Exploitation

A significant vulnerability has been identified in large language models (LLMs) such as ChatGPT,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension

SectopRAT, also known as Arechclient2, is a sophisticated Remote Access Trojan (RAT) developed using...

Threat Actors Trojanize Popular Games to Evade Security and Infect Systems

A sophisticated malware campaign was launched by cybercriminals, targeting users through trojanized versions of...

New Research Aims to Strengthen MITRE ATT&CK for Evolving Cyber Threats

A recent study by researchers from the National University of Singapore and NCS Cyber...