cognitive cybersecurity intelligence

News and Analysis

Search

North Korean Hackers Use ZIP Files to Deploy Malicious PowerShell Scripts

North Korean state-sponsored hackers, known as APT37 or ScarCruft, are leveraging malicious ZIP files in phishing emails to start multi-stage cyber attacks. The malicious files, disguised as North Korean documents or trade agreements, use scripts and batch files to deploy the RokRat remote access Trojan, which gathers system information that is then sent to command-and-control servers via popular cloud services. The malware can also execute remote commands for data exfiltration, system reconnaissance, and process termination.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts