Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Openai and human researchers condemn “reckless” safety culture at Elon Musk’s Xai

GM teams up with Redwood Materials to power data center with EV batteries

Hackers leverage Microsoft Teams to spread Mathambuchas 3.0 malware to targeted businesses

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Space Pirates targets Russian IT companies with new Luckystrike agent malware
Identity

Space Pirates targets Russian IT companies with new Luckystrike agent malware

userBy userFebruary 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 27, 2025Ravi LakshmananMalware/Network Security

Luckystrike Agent Malware

The threat actor, known as Space Pirates, is linked to a malicious campaign targeting Russian information technology (IT) organizations with previously undocumented malware called Luckystrike agents.

The activity was detected in November 2024 by Solar, the cybersecurity unit of Russian state-owned telecommunications company Rostelecom. I’m tracking my activities under the name Erudite Mogwai.

The attack is also characterized by the use of other tools such as Deed Rat, also known as Shadowpad Light, and the use of a customized version of a proxy utility named Stowaway that was previously used by other China-related hacking groups.

Cybersecurity

“Erudite Mogwai is one of the active APT groups specializing in confidential information and theft of spies,” the solar researcher said. “Since at least 2017, the group has attacked government agencies, IT departments of various organizations, and companies related to high-tech industries such as aerospace and electricity.”

Threat Actor was first published in 2022 by Positive Technology, detailing the exclusive use of Deed Rat Malware. This group is thought to share a tactical overlap with another hacking group called WebWorm. It is known to target organizations in Russia, Georgia and Mongolian.

In one of the attacks targeting customers in the government sector, Solar said that attackers have been discovered deploying various tools to promote reconnaissance, and at the same time dropping a multi-function .NET backdoor (C2) using Microsoft OneDrive for command and control.

“Attackers have access to infrastructure by March 2023 by compromising publicly accessible web services, starting to look for “low hanging fruit” in the infrastructure,” Solar said. “In 19 months, the attackers slowly spread across the customer’s systems until they reached a network segment connected to surveillance in November 2024.”

Cybersecurity

Also noteworthy is that it incorporates XXTEA as a encryption algorithm and uses LZ4 as a compression algorithm that adds support for the QUIC transport protocol, as well as using the modified version of Stowaway to preserve only the proxy functionality.

“Erudite Mogwai has begun a journey to modify this utility by reducing the functionality that is not needed,” Solar said. “They continued to do minor edits, such as renaming features and resizing structures (probably to knock down existing detection signatures). At this point, the version of Stowaway used in this group is called a full-fledged fork.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleExplosion, gunfight kills some at Dr. Congo’s M23 rally | Conflict News
Next Article Latest bid offers worth $91.5 billion in stripes, delays in IPO plans
user
  • Website

Related Posts

Hackers leverage Microsoft Teams to spread Mathambuchas 3.0 malware to targeted businesses

July 16, 2025

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

July 16, 2025

Fully patched Sonic Wall SMA 100 Series Device with UNC6148 Backdoor of Step Rootkit

July 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Openai and human researchers condemn “reckless” safety culture at Elon Musk’s Xai

GM teams up with Redwood Materials to power data center with EV batteries

Hackers leverage Microsoft Teams to spread Mathambuchas 3.0 malware to targeted businesses

GMC Hummer Ev surpassed Tesla Cybertruck’s last quarter

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.