Interesting "New" Hacking Tools
Hello,
I came across this article in my google feed this past week and it caught my eye. It was about a tool that was used to hack "air-gapped" devices. Granted I wasn't familiar with that term until I read this article and then proceeded to look it up in more detail. The tools have been attributed to a group being called "GoldenJackle". The tools involved in the hack included a backdoor under the name "JackalControl", a file collector and exfiltrator, and then a worm facilitates other parts of the attack on the external drive.
The attack is described by article as:
"The basic flow of the attack is, first, infecting an Internet-connected device through a means ESET and Kaspersky have been unable to determine. Next, the infected computer infects any external drives that get inserted. When the infected drive is plugged into an air-gapped system, it collects and stores data of interest. Last, when the drive is inserted into the Internet-connected device, the data is transferred to an attacker-controlled server."
Source: Two never-before-seen tools, from same group, infect air-gapped devices
I found this to be very interesting as I had never really explored the kinds of strategies that would need to be adopted in order to hack a machine that isn't part of the network. I would have probably thought such a machine was nearly unhackable in all honesty. It really goes to show just how creative hackers can be when it comes to penetrating systems that we want to protect.
Comments
Post a Comment