BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to run commands, move files, and route traffic after they have already entered a network, raising the risk to internal systems and sensitive data. The attack begins after the attackers gain access and move laterally through the victim environment using SSH. From there, they deploy a loader that launches the backdoor, a method that reflects the group’s established interest in stealthy network access, including earlier BlackTech router intrusion activity targeting corporate networks. Analysts at IIJ Security...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!