CISA Warns of New RAT Aimed at US Defense Contractors

Hidden Cobra, an APT group associated with the government of North Korea, is thought to be behind the campaign.

The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has issued a Malware Analysis Report on BLINDINGCAN, a new remote-access Trojan variant used by North Korean threat actors. According to the report, the FBI has high confidence that Hidden Cobra, an APT group known to be associated with the government of North Korea, is using BLINDINGCAN to establish a presence on networks and exfiltrate data.

CISA says Hidden Cobra targeted government contractors earlier this year in an attempt to gather intelligence surrounding key military and energy technologies. The documents used in the campaign featured job postings from defense contractors as lures and, when opened, installed BLINDINGCAN  on the victims' systems.

The report recommends organizations follow best practices regarding malicious email messages to avoid being infected by the malware.

Read more here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Recommended Reading:

Comment  | 
Email This  | 
Print  | 
More Insights
Copyright © 2021 UBM Electronics, A UBM company, All rights reserved. Privacy Policy | Terms of Service