* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, March 7, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Las Vegas A’s, Will Guidara, and Aramark Sports + Entertainment Reveal Vision for First-of-its-Kind Athletic Club Behind Home Plate of A’s New Ballpark – Business Wire

    SBCC Theatre Group Brings ‘A Small Family Business’ to Life on Stage

    Play, Relax & Have Fun: Enjoy Your Spring Break in Arlington – City of Arlington (.gov)

    What Caused Webtoon Entertainment Stock to Plummet on Wednesday?

    Opening date set for Cosm entertainment venue at Centennial Yards – WALB

    Banijay, All3Media to merge entertainment businesses – WKZO

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    A Century and a Half of Connectivity: Professor Mojtaba Vaezi Reflects on the Evolution and Future of Communication Technology

    The Technology Patients and Clinicians Truly Want: What You Need to Know

    Shift Technology and AXA Join Forces for Five More Years to Drive AI-Powered Insurance Innovation

    Middle Bucks Institute of Technology Shines as National Rookie of the Year at NAHB Student Competition

    Brainhole Technology Elevates Portfolio with $1.3 Million Investment in Applied Optoelectronics

    Upway Accelerates Innovation with Exciting New Chief Technology Officer Appointment

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Las Vegas A’s, Will Guidara, and Aramark Sports + Entertainment Reveal Vision for First-of-its-Kind Athletic Club Behind Home Plate of A’s New Ballpark – Business Wire

    SBCC Theatre Group Brings ‘A Small Family Business’ to Life on Stage

    Play, Relax & Have Fun: Enjoy Your Spring Break in Arlington – City of Arlington (.gov)

    What Caused Webtoon Entertainment Stock to Plummet on Wednesday?

    Opening date set for Cosm entertainment venue at Centennial Yards – WALB

    Banijay, All3Media to merge entertainment businesses – WKZO

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    A Century and a Half of Connectivity: Professor Mojtaba Vaezi Reflects on the Evolution and Future of Communication Technology

    The Technology Patients and Clinicians Truly Want: What You Need to Know

    Shift Technology and AXA Join Forces for Five More Years to Drive AI-Powered Insurance Innovation

    Middle Bucks Institute of Technology Shines as National Rookie of the Year at NAHB Student Competition

    Brainhole Technology Elevates Portfolio with $1.3 Million Investment in Applied Optoelectronics

    Upway Accelerates Innovation with Exciting New Chief Technology Officer Appointment

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Ukraine says hackers abuse SyncThing data sync tool to steal data

June 7, 2024
in Technology
Ukraine says hackers abuse SyncThing data sync tool to steal data
Share on FacebookShare on Twitter

Metal hand between sync cables

The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed “SickSync,” launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.

The threat group is linked to the Luhansk People’s Republic (LPR) region, which Russia has occupied almost in its entirety since October 2022. The hacker’s activities commonly align with Russia’s interests.

The attack utilizes the legitimate file-syncing software SyncThing in combination with malware called SPECTR.

Vermin’s apparent motive is to steal sensitive information from military organizations.

Attack details

The attack begins with a phishing email sent to the target, carrying a password-protected RARSFX archive named “turrel.fop.wolf.rar.”

Email sent to targetsEmail sent to targets
Source: CERT-UA

Upon launching the file, it extracts a PDF (“Wowchok.pdf”), an installer (“sync.exe”), and a BAT script (“run_user.bat”). The BAT executes sync.exe, which contains SyncThing and SPECTR malware, along with the required libraries.

Contents of the RAR archiveContents of the RAR archive
Source: CERT-UA

SyncThing establishes a peer-to-peer connection for data synchronization, which is used for stealing documents and account passwords.

The legitimate tool is modified with new directory names and scheduled tasks to evade identification, while the component that displays a window when it’s active has been removed.

SPECTR is a modular malware that has the following capabilities:

SpecMon: Calls PluginLoader.dll to execute DLLs containing the “IPlugin” class.
Screengrabber: Takes screenshots every 10 seconds when specific program windows are detected.
FileGrabber: Uses robocopy.exe to copy files from user directories such as Desktop, MyPictures, Downloads, OneDrive, and DropBox.
Usb: Copies files from removable USB media.
Social: Steals authentication data from various messengers like Telegram, Signal, Skype, and Element.
Browsers: Steals data from browsers including Firefox, Edge, and Chrome, focusing on authentication data, session information, and browsing history.

Data stolen by SPECTR is copied into subfolders within the ‘%APPDATA%syncServe_Sync’ directory and subsequently transferred through syncing to the threat actor’s system.

The two components deployed by VerminThe two components deployed by Vermin
Source: CERT-UA

CERT-UA believes Vermin decided to use a legitimate tool for data exfiltration to reduce the likelihood of security systems flagging the network traffic as suspicious.

The cybersecurity agency notes that any interaction with SyncThing’s infrastructure (e.g., *.syncthing.net) should be enough to consider a system compromised and launch an investigation to detect and uproot the infection.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/ukraine-says-hackers-abuse-syncthing-data-sync-tool-to-steal-data/

Tags: hackerstechnologyUkraine
Previous Post

New Fog ransomware targets US education sector via breached VPNs

Next Post

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

Inside the Daring Mission to Rescue Indian Creek

March 7, 2026

Unlocking Innovation: How Chemist Lily Robertson is Revolutionizing Autonomous Discovery to Accelerate Scientific Breakthroughs

March 7, 2026

NASA Confirms: No Asteroid Threat to the Moon in 2032

March 7, 2026

Sign up for North Jersey Living; Our real estate, lifestyle newsletter – Yahoo

March 7, 2026

Boston’s World Cup games still in doubt after funding shortfall proposal rejected – The New York Times

March 7, 2026

Alaska 2025 summer tourism was ‘soft’ amid economic jitters and reduced marketing money – Anchorage Daily News

March 7, 2026

Las Vegas A’s, Will Guidara, and Aramark Sports + Entertainment Reveal Vision for First-of-its-Kind Athletic Club Behind Home Plate of A’s New Ballpark – Business Wire

March 7, 2026

Governor Newsom announces major transformation of six vacant buildings in Los Angeles County into mental health and housing communities – California State Portal | CA.gov

March 7, 2026

Popular prediction markets take heat from lawmakers – Spectrum News

March 7, 2026

A Century and a Half of Connectivity: Professor Mojtaba Vaezi Reflects on the Evolution and Future of Communication Technology

March 7, 2026

Categories

Archives

March 2026
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
3031  
« Feb    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,105)
  • Economy (1,124)
  • Entertainment (22,001)
  • General (20,270)
  • Health (10,162)
  • Lifestyle (1,138)
  • News (22,149)
  • People (1,129)
  • Politics (1,141)
  • Science (16,339)
  • Sports (21,626)
  • Technology (16,106)
  • World (1,116)

Recent News

Inside the Daring Mission to Rescue Indian Creek

March 7, 2026

Unlocking Innovation: How Chemist Lily Robertson is Revolutionizing Autonomous Discovery to Accelerate Scientific Breakthroughs

March 7, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version