Distribution of Malware Abusing LogMeIn and PDQ Connect

Distribution of Malware Abusing LogMeIn and PDQ Connect

AhnLab SEcurity intelligence Center (ASEC) recently identified cases of attacks abusing the RMM (Remote Monitoring and Management) tools LogMeIn Resolve (GoTo Resolve) and PDQ Connect. While the initial distribution method is unknown, the attacks involve a legitimate-looking website that disguises the malware as a normal program. When a user downloads

Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)

Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)

AhnLab SEcurity intelligence Center (ASEC) has identified the details of the Kimsuky threat group recently exploiting a vulnerability (CVE-2017-11882) in the equation editor included in MS Office (EQNEDT32.EXE) to distribute a keylogger. The threat actor distributed the keylogger by exploiting the vulnerability to run a page with an embedded malicious