Lazarus Group Using New WinorDLL64 Backdoor to Exfiltrate Sensitive Data

Discussion in 'News Aggregator' started by The Hacker News, 23 Feb 2023.

  1. A new backdoor associated with a malware downloader named Wslink has been discovered, with the tool likely used by the notorious North Korea-aligned Lazarus Group, new findings reveal. The payload, dubbed WinorDLL64 by ESET, is a fully-featured implant that can exfiltrate, overwrite, and delete files; execute PowerShell commands; and obtain comprehensive information about the underlying machine.

    Continue reading...
     

Share This Page

Loading...