These Hackers Used Log4Shell Vulnerability To Target Us Energy Firms
Cisco’s Talos security analysts say Lazarus hackers are exploiting flaws in Log4J – an open-source application logging component – in unpatched internet-facing VMware Horizon servers to gain initial access at energy providers in the US, Canada, and Japan. The North Korea-backed attackers deploy custom malware for long-term espionage. Lazarus, also tracked as Hidden Cobra and APT38, is known for stealing hundreds of millions in cryptocurrency from crypto firms. The US Treasury sanctioned Lazarus in 2019 for crypto and banking system heists that it said helped raise revenues to fund North Korea’s nuclear weapons and ballistic missile programs....