* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, April 11, 2026
Earth-News
  • Home
  • Business
  • Entertainment
  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Wall Street Analysts Are Excited About These Top Technology Stocks

    SiFive raises $400 million from Atreides, Nvidia for data-center chip technology – Reuters

    How Urbana Police Are Using Cutting-Edge Technology to Protect the Community

    RNA Alone Doesn’t Tell the Full Immune Story – Technology Networks

    Avalanche Energy Awarded $5.2M DARPA Contract to Develop Radioisotope Power Technology – PR Newswire

    Rochester Institute of Technology to Offer Bachelor’s in AI – GovTech

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Wall Street Analysts Are Excited About These Top Technology Stocks

    SiFive raises $400 million from Atreides, Nvidia for data-center chip technology – Reuters

    How Urbana Police Are Using Cutting-Edge Technology to Protect the Community

    RNA Alone Doesn’t Tell the Full Immune Story – Technology Networks

    Avalanche Energy Awarded $5.2M DARPA Contract to Develop Radioisotope Power Technology – PR Newswire

    Rochester Institute of Technology to Offer Bachelor’s in AI – GovTech

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Ukraine says hackers abuse SyncThing data sync tool to steal data

June 7, 2024
in Technology
Ukraine says hackers abuse SyncThing data sync tool to steal data
Share on FacebookShare on Twitter

Metal hand between sync cables

The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed “SickSync,” launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.

The threat group is linked to the Luhansk People’s Republic (LPR) region, which Russia has occupied almost in its entirety since October 2022. The hacker’s activities commonly align with Russia’s interests.

The attack utilizes the legitimate file-syncing software SyncThing in combination with malware called SPECTR.

Vermin’s apparent motive is to steal sensitive information from military organizations.

Attack details

The attack begins with a phishing email sent to the target, carrying a password-protected RARSFX archive named “turrel.fop.wolf.rar.”

Email sent to targetsEmail sent to targets
Source: CERT-UA

Upon launching the file, it extracts a PDF (“Wowchok.pdf”), an installer (“sync.exe”), and a BAT script (“run_user.bat”). The BAT executes sync.exe, which contains SyncThing and SPECTR malware, along with the required libraries.

Contents of the RAR archiveContents of the RAR archive
Source: CERT-UA

SyncThing establishes a peer-to-peer connection for data synchronization, which is used for stealing documents and account passwords.

The legitimate tool is modified with new directory names and scheduled tasks to evade identification, while the component that displays a window when it’s active has been removed.

SPECTR is a modular malware that has the following capabilities:

SpecMon: Calls PluginLoader.dll to execute DLLs containing the “IPlugin” class.
Screengrabber: Takes screenshots every 10 seconds when specific program windows are detected.
FileGrabber: Uses robocopy.exe to copy files from user directories such as Desktop, MyPictures, Downloads, OneDrive, and DropBox.
Usb: Copies files from removable USB media.
Social: Steals authentication data from various messengers like Telegram, Signal, Skype, and Element.
Browsers: Steals data from browsers including Firefox, Edge, and Chrome, focusing on authentication data, session information, and browsing history.

Data stolen by SPECTR is copied into subfolders within the ‘%APPDATA%syncServe_Sync’ directory and subsequently transferred through syncing to the threat actor’s system.

The two components deployed by VerminThe two components deployed by Vermin
Source: CERT-UA

CERT-UA believes Vermin decided to use a legitimate tool for data exfiltration to reduce the likelihood of security systems flagging the network traffic as suspicious.

The cybersecurity agency notes that any interaction with SyncThing’s infrastructure (e.g., *.syncthing.net) should be enough to consider a system compromised and launch an investigation to detect and uproot the infection.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/ukraine-says-hackers-abuse-syncthing-data-sync-tool-to-steal-data/

Tags: hackerstechnologyUkraine
Previous Post

New Fog ransomware targets US education sector via breached VPNs

Next Post

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

Kazakhstan to Spearhead Energy Transition at 2026 Regional Ecological Summit

April 11, 2026

Thomas College Ignites Curiosity at Its Exciting 2nd Annual Girls in Science Day

April 11, 2026

White House Unveils Plan to Slash Funding for 54 Key NASA Science Missions

April 11, 2026

Mad scramble for eggs – Coastal Point

April 11, 2026

Is Renting Out Your Home During the World Cup a Game-Changer for Your Income?

April 11, 2026

What World War I’s Economic Fallout Teaches Us About a Future That Could Be Even More Devastating

April 11, 2026

Hershey Theatre Rock Show Postponed Due to Plumbing Problem: Essential Updates Inside

April 11, 2026

Quiz: This week in politics – WBAL News Radio

April 11, 2026

Wall Street Analysts Are Excited About These Top Technology Stocks

April 11, 2026

How Sports Stars, Hip-Hop Icons, and Celebrity Magicians Are Influencing Landmark Supreme Court Battles

April 11, 2026

Categories

Archives

April 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Mar    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,163)
  • Economy (1,183)
  • Entertainment (22,059)
  • General (20,922)
  • Health (10,218)
  • Lifestyle (1,197)
  • News (22,149)
  • People (1,185)
  • Politics (1,201)
  • Science (16,398)
  • Sports (21,683)
  • Technology (16,165)
  • World (1,174)

Recent News

Kazakhstan to Spearhead Energy Transition at 2026 Regional Ecological Summit

April 11, 2026

Thomas College Ignites Curiosity at Its Exciting 2nd Annual Girls in Science Day

April 11, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version