* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, April 19, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Rocky” Celebrates Its Golden 50th Anniversary with a Knockout Theatrical Return November 7-11

    From Lee Cronin’s The Mummy to Zayn: Your Ultimate Entertainment Guide for the Week Ahead

    Meghan Trainor Cancels Tour, Hershey Stop Among Affected Dates

    April’s History Happy Hour Takes Flight!

    Atomic Heart Explodes with Excitement! DLC #4 “Blood on Crystal” and Ultimate Edition Now Available

    Exciting New Restaurant, Bar, and Entertainment Venue Coming to Maryville!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    26 Brilliant Strategies to Keep Your Technology Agile as Your Business Expands

    Med Center Health Launches Revolutionary Mobile MRI Technology

    Can Western Digital Surge Ahead of Seagate Technology in the Upcoming Rally?

    Unveiling the Journey of Radionuclide Cancer Drugs Within Living Cells

    Face of Marketing and Business Solutions: Taneja Marketing/Liftoff Technology – Arkansas Money & Politics

    Big IPOs could be good news for California budget – sfexaminer.com

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Rocky” Celebrates Its Golden 50th Anniversary with a Knockout Theatrical Return November 7-11

    From Lee Cronin’s The Mummy to Zayn: Your Ultimate Entertainment Guide for the Week Ahead

    Meghan Trainor Cancels Tour, Hershey Stop Among Affected Dates

    April’s History Happy Hour Takes Flight!

    Atomic Heart Explodes with Excitement! DLC #4 “Blood on Crystal” and Ultimate Edition Now Available

    Exciting New Restaurant, Bar, and Entertainment Venue Coming to Maryville!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    26 Brilliant Strategies to Keep Your Technology Agile as Your Business Expands

    Med Center Health Launches Revolutionary Mobile MRI Technology

    Can Western Digital Surge Ahead of Seagate Technology in the Upcoming Rally?

    Unveiling the Journey of Radionuclide Cancer Drugs Within Living Cells

    Face of Marketing and Business Solutions: Taneja Marketing/Liftoff Technology – Arkansas Money & Politics

    Big IPOs could be good news for California budget – sfexaminer.com

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Ukraine says hackers abuse SyncThing data sync tool to steal data

June 7, 2024
in Technology
Ukraine says hackers abuse SyncThing data sync tool to steal data
Share on FacebookShare on Twitter

Metal hand between sync cables

The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed “SickSync,” launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.

The threat group is linked to the Luhansk People’s Republic (LPR) region, which Russia has occupied almost in its entirety since October 2022. The hacker’s activities commonly align with Russia’s interests.

The attack utilizes the legitimate file-syncing software SyncThing in combination with malware called SPECTR.

Vermin’s apparent motive is to steal sensitive information from military organizations.

Attack details

The attack begins with a phishing email sent to the target, carrying a password-protected RARSFX archive named “turrel.fop.wolf.rar.”

Email sent to targetsEmail sent to targets
Source: CERT-UA

Upon launching the file, it extracts a PDF (“Wowchok.pdf”), an installer (“sync.exe”), and a BAT script (“run_user.bat”). The BAT executes sync.exe, which contains SyncThing and SPECTR malware, along with the required libraries.

Contents of the RAR archiveContents of the RAR archive
Source: CERT-UA

SyncThing establishes a peer-to-peer connection for data synchronization, which is used for stealing documents and account passwords.

The legitimate tool is modified with new directory names and scheduled tasks to evade identification, while the component that displays a window when it’s active has been removed.

SPECTR is a modular malware that has the following capabilities:

SpecMon: Calls PluginLoader.dll to execute DLLs containing the “IPlugin” class.
Screengrabber: Takes screenshots every 10 seconds when specific program windows are detected.
FileGrabber: Uses robocopy.exe to copy files from user directories such as Desktop, MyPictures, Downloads, OneDrive, and DropBox.
Usb: Copies files from removable USB media.
Social: Steals authentication data from various messengers like Telegram, Signal, Skype, and Element.
Browsers: Steals data from browsers including Firefox, Edge, and Chrome, focusing on authentication data, session information, and browsing history.

Data stolen by SPECTR is copied into subfolders within the ‘%APPDATA%syncServe_Sync’ directory and subsequently transferred through syncing to the threat actor’s system.

The two components deployed by VerminThe two components deployed by Vermin
Source: CERT-UA

CERT-UA believes Vermin decided to use a legitimate tool for data exfiltration to reduce the likelihood of security systems flagging the network traffic as suspicious.

The cybersecurity agency notes that any interaction with SyncThing’s infrastructure (e.g., *.syncthing.net) should be enough to consider a system compromised and launch an investigation to detect and uproot the infection.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/ukraine-says-hackers-abuse-syncthing-data-sync-tool-to-steal-data/

Tags: hackerstechnologyUkraine
Previous Post

New Fog ransomware targets US education sector via breached VPNs

Next Post

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

2026 WGI Percussion and Winds World Championship Finals: Full Scores Revealed

April 19, 2026

Why Nothing Is Going Putin’s Way

April 19, 2026

Rocky” Celebrates Its Golden 50th Anniversary with a Knockout Theatrical Return November 7-11

April 19, 2026

Obama and Mamdani Share a Special Moment in New York City Before a Delightful Preschool Storytime

April 19, 2026

26 Brilliant Strategies to Keep Your Technology Agile as Your Business Expands

April 19, 2026

Marissa McCann’s Dominant Pitch Ignites an Unforgettable Softball Showdown

April 19, 2026

Breathing Easier Together: Innovative Solutions Transforming Community Air Quality

April 19, 2026

Physicists Awarded $3M Prize for Cracking the Mysteries of Muons

April 19, 2026

Scientists Reveal Surprising Barrier Hindering Ozone Layer Recovery

April 18, 2026

Colorado Woman Overcomes Health Challenges to Make Triumphant Boston Marathon Comeback

April 18, 2026

Categories

Archives

April 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Mar    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,174)
  • Economy (1,197)
  • Entertainment (22,072)
  • General (21,054)
  • Health (10,228)
  • Lifestyle (1,207)
  • News (22,149)
  • People (1,195)
  • Politics (1,215)
  • Science (16,409)
  • Sports (21,695)
  • Technology (16,179)
  • World (1,187)

Recent News

2026 WGI Percussion and Winds World Championship Finals: Full Scores Revealed

April 19, 2026

Why Nothing Is Going Putin’s Way

April 19, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version