U.S CISA recently noticed that hackers using Phishing Emails to deploy KONNNI malware with the help of weaponized Microsoft word documents.
The KONNI RAT was initially found in May 2017 by researchers at the Cisco Talos team after it was operated in attacks that are aimed at businesses linked to North Korea.
KONNI has been applied in highly targeted attacks only; these include the United Nations, UNICEF, and entities linked to North Korea. Moreover, the expert’s also classified a link between KONNI and DarkHotel.
The KONNI vulnerability is typically spread through phishing emails holding a Microsoft Word file with an ill-disposed Visual Basic Application (VBA) macro code to deploy the malware.
The CISA explains that the macro code was created to change the font color to fool the victim into allowing the content, check whether the system design is 32-bit or 64-bit.
It also creates and runs a command line to download further additional files, while the certificate database tool CertUtil is applied for the download of remote files.
The CISA suggested users and administrators apply the following points to increase the security aspect of their company’s network systems:-
Apart from this, the CISA suggested the users to follow the recommended mitigations carefully so that they can keep themselves protected from all unwanted malicious malware.
Moreover, the security researchers at CISA are still investigating the whole matter, and they asserted that all the users must follow every recommendation carefully.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Also Read;
Citrix Warns That Hackers May Exploit the New Patched Flaw Quickly
US GOV Exposes Chinese Espionage Malware “TAIDOOR” Secretly Used To For a Decade
PowerDNS has issued an urgent security advisory for its DNSdist software, warning users of a…
WhatsApp, the world’s most popular messaging platform, has announced a major expansion of artificial intelligence…
A major set of vulnerabilities-collectively named “AirBorne”-in Apple’s AirPlay protocol and SDK have been unveiled,…
Google has begun rolling out Chrome 136 to the stable channel for Windows, Mac, and…
Cybersecurity researchers at Hunt have uncovered a server hosting advanced malicious tools, including SuperShell command-and-control…
A sophisticated cyberattack targeted senior members of the World Uyghur Congress (WUC), the largest Uyghur…