Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

How a hardware wallet protects your private key: Security and safety instructions

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Review Week: Meta reveals Oakley Smart Glasses

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Space Pirates targets Russian IT companies with new Luckystrike agent malware
Identity

Space Pirates targets Russian IT companies with new Luckystrike agent malware

userBy userFebruary 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 27, 2025Ravi LakshmananMalware/Network Security

Luckystrike Agent Malware

The threat actor, known as Space Pirates, is linked to a malicious campaign targeting Russian information technology (IT) organizations with previously undocumented malware called Luckystrike agents.

The activity was detected in November 2024 by Solar, the cybersecurity unit of Russian state-owned telecommunications company Rostelecom. I’m tracking my activities under the name Erudite Mogwai.

The attack is also characterized by the use of other tools such as Deed Rat, also known as Shadowpad Light, and the use of a customized version of a proxy utility named Stowaway that was previously used by other China-related hacking groups.

Cybersecurity

“Erudite Mogwai is one of the active APT groups specializing in confidential information and theft of spies,” the solar researcher said. “Since at least 2017, the group has attacked government agencies, IT departments of various organizations, and companies related to high-tech industries such as aerospace and electricity.”

Threat Actor was first published in 2022 by Positive Technology, detailing the exclusive use of Deed Rat Malware. This group is thought to share a tactical overlap with another hacking group called WebWorm. It is known to target organizations in Russia, Georgia and Mongolian.

In one of the attacks targeting customers in the government sector, Solar said that attackers have been discovered deploying various tools to promote reconnaissance, and at the same time dropping a multi-function .NET backdoor (C2) using Microsoft OneDrive for command and control.

“Attackers have access to infrastructure by March 2023 by compromising publicly accessible web services, starting to look for “low hanging fruit” in the infrastructure,” Solar said. “In 19 months, the attackers slowly spread across the customer’s systems until they reached a network segment connected to surveillance in November 2024.”

Cybersecurity

Also noteworthy is that it incorporates XXTEA as a encryption algorithm and uses LZ4 as a compression algorithm that adds support for the QUIC transport protocol, as well as using the modified version of Stowaway to preserve only the proxy functionality.

“Erudite Mogwai has begun a journey to modify this utility by reducing the functionality that is not needed,” Solar said. “They continued to do minor edits, such as renaming features and resizing structures (probably to knock down existing detection signatures). At this point, the version of Stowaway used in this group is called a full-fledged fork.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleExplosion, gunfight kills some at Dr. Congo’s M23 rally | Conflict News
Next Article Latest bid offers worth $91.5 billion in stripes, delays in IPO plans
user
  • Website

Related Posts

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

June 21, 2025

Qilin ransomware adds “Cole Lawyer” feature that puts pressure on victims for larger ransoms

June 20, 2025

Television in Iranian states hijacked mid-distance broadcasts amid geopolitical tensions. $90 million stolen from Crypto Heist

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How a hardware wallet protects your private key: Security and safety instructions

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Review Week: Meta reveals Oakley Smart Glasses

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

How a hardware wallet protects your private key: Security and safety instructions

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Apple is talking to you to win AI startup confusion

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.