* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, March 26, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Entertainment Tonight and Inside Edition Get Renewal News at CBS Media Ventures – Yahoo

    Aramark Sports + Entertainment’s Culinary Creativity Takes the Field at Eight MLB Stadiums as Umpires Shout “Play Ball!” – Aramark

    Lucas Ball Joins Forces with Twelve6 Entertainment in Thrilling New Partnership

    Fall River’s Day of Portugal announces dates, entertainment lineup for 2026 – Fall River Reporter

    Margaret Cho Opens Up About Comedy, Politics, and Life in Hollywood

    Bring Spring Freshness to Your Kitchen with Expert Chef Tips

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    One Tank Trips: Exploring the Museum of Music Technology – 6abc Philadelphia

    Tennessee Lawmakers Push Ahead with Bill to Limit Technology Use in Elementary Schools

    Datasea Launches First U.S. Commercial Acoustic Technology-Powered Wellness Care Robots, Paving the Way for Future Innovation

    Get in the Game: Spring Athletics Challenge at Rochester Institute of Technology

    How Prophetic Land Search Company is Revolutionizing Technology to Transform the Industry

    Is MACOM Technology Solutions (MTSI) the Next Big Opportunity After Its Recent Price Drop?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Entertainment Tonight and Inside Edition Get Renewal News at CBS Media Ventures – Yahoo

    Aramark Sports + Entertainment’s Culinary Creativity Takes the Field at Eight MLB Stadiums as Umpires Shout “Play Ball!” – Aramark

    Lucas Ball Joins Forces with Twelve6 Entertainment in Thrilling New Partnership

    Fall River’s Day of Portugal announces dates, entertainment lineup for 2026 – Fall River Reporter

    Margaret Cho Opens Up About Comedy, Politics, and Life in Hollywood

    Bring Spring Freshness to Your Kitchen with Expert Chef Tips

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    One Tank Trips: Exploring the Museum of Music Technology – 6abc Philadelphia

    Tennessee Lawmakers Push Ahead with Bill to Limit Technology Use in Elementary Schools

    Datasea Launches First U.S. Commercial Acoustic Technology-Powered Wellness Care Robots, Paving the Way for Future Innovation

    Get in the Game: Spring Athletics Challenge at Rochester Institute of Technology

    How Prophetic Land Search Company is Revolutionizing Technology to Transform the Industry

    Is MACOM Technology Solutions (MTSI) the Next Big Opportunity After Its Recent Price Drop?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Ukraine says hackers abuse SyncThing data sync tool to steal data

June 7, 2024
in Technology
Ukraine says hackers abuse SyncThing data sync tool to steal data
Share on FacebookShare on Twitter

Metal hand between sync cables

The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed “SickSync,” launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.

The threat group is linked to the Luhansk People’s Republic (LPR) region, which Russia has occupied almost in its entirety since October 2022. The hacker’s activities commonly align with Russia’s interests.

The attack utilizes the legitimate file-syncing software SyncThing in combination with malware called SPECTR.

Vermin’s apparent motive is to steal sensitive information from military organizations.

Attack details

The attack begins with a phishing email sent to the target, carrying a password-protected RARSFX archive named “turrel.fop.wolf.rar.”

Email sent to targetsEmail sent to targets
Source: CERT-UA

Upon launching the file, it extracts a PDF (“Wowchok.pdf”), an installer (“sync.exe”), and a BAT script (“run_user.bat”). The BAT executes sync.exe, which contains SyncThing and SPECTR malware, along with the required libraries.

Contents of the RAR archiveContents of the RAR archive
Source: CERT-UA

SyncThing establishes a peer-to-peer connection for data synchronization, which is used for stealing documents and account passwords.

The legitimate tool is modified with new directory names and scheduled tasks to evade identification, while the component that displays a window when it’s active has been removed.

SPECTR is a modular malware that has the following capabilities:

SpecMon: Calls PluginLoader.dll to execute DLLs containing the “IPlugin” class.
Screengrabber: Takes screenshots every 10 seconds when specific program windows are detected.
FileGrabber: Uses robocopy.exe to copy files from user directories such as Desktop, MyPictures, Downloads, OneDrive, and DropBox.
Usb: Copies files from removable USB media.
Social: Steals authentication data from various messengers like Telegram, Signal, Skype, and Element.
Browsers: Steals data from browsers including Firefox, Edge, and Chrome, focusing on authentication data, session information, and browsing history.

Data stolen by SPECTR is copied into subfolders within the ‘%APPDATA%syncServe_Sync’ directory and subsequently transferred through syncing to the threat actor’s system.

The two components deployed by VerminThe two components deployed by Vermin
Source: CERT-UA

CERT-UA believes Vermin decided to use a legitimate tool for data exfiltration to reduce the likelihood of security systems flagging the network traffic as suspicious.

The cybersecurity agency notes that any interaction with SyncThing’s infrastructure (e.g., *.syncthing.net) should be enough to consider a system compromised and launch an investigation to detect and uproot the infection.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/ukraine-says-hackers-abuse-syncthing-data-sync-tool-to-steal-data/

Tags: hackerstechnologyUkraine
Previous Post

New Fog ransomware targets US education sector via breached VPNs

Next Post

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

Next Gen Creators: Unveiling the Future of Synthetic Innovation

March 25, 2026

Meet the Trailblazing Scientists Chosen for the 2026 Schmidt Science Fellows Cohort

March 25, 2026

Discover the Wonders of the Universe at Science Central’s New Planetarium!

March 25, 2026

Meet the Pampered Squirrel Living a Surprisingly Luxurious Life in Viral Videos

March 25, 2026

Dallas police receive $22 million for FIFA World Cup security measures, including more funding for drones and cameras – WFAA

March 25, 2026

More Than Food: Agriculture’s Economic Footprint – American Farm Bureau Federation

March 25, 2026

Entertainment Tonight and Inside Edition Get Renewal News at CBS Media Ventures – Yahoo

March 25, 2026

Providing quality, access to health care in rural Indonesia – Harvard T.H. Chan School of Public Health

March 25, 2026

Unraveling Playground Politics: The Hidden Dynamics at Play

March 25, 2026

One Tank Trips: Exploring the Museum of Music Technology – 6abc Philadelphia

March 25, 2026

Categories

Archives

March 2026
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
3031  
« Feb    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,137)
  • Economy (1,155)
  • Entertainment (22,031)
  • General (20,615)
  • Health (10,193)
  • Lifestyle (1,169)
  • News (22,149)
  • People (1,157)
  • Politics (1,173)
  • Science (16,370)
  • Sports (21,656)
  • Technology (16,137)
  • World (1,148)

Recent News

Next Gen Creators: Unveiling the Future of Synthetic Innovation

March 25, 2026

Meet the Trailblazing Scientists Chosen for the 2026 Schmidt Science Fellows Cohort

March 25, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version