North Korean Andariel Threat Group Adds New Earlyrat Malware To Its Phishing Campaign
In mid-2022, the threat actor Andariel was known for using the DTrack malware and Maui ransomware. To breach its target’s network, Andariel also exploited the Log4j vulnerability, while introducing several types of new malware, like YamaBot, MagicRat and updated versions of NukeSpeed and DTrack. EarlyRAT was discovered by Kaspersky in an unrelated investigation while looking into Andariel’s campaign. It was observed that the threat group infected its target’s machine by executing a Log4j exploit, which further downloaded malwares from a C2 (command & control) server....