• Menu
  • Skip to main content
  • Skip to primary sidebar

All Tech News

Latest Technology News

New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War

You are here: Home / Cyber Security News / New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War

Amid the ongoing war among Russia and Ukraine, govt, agriculture, and transportation organizations located in Donetsk, Lugansk, and Crimea have been attacked as section of an active campaign that drops a formerly unseen, modular framework dubbed CommonMagic.

“Though the initial vector of compromise is unclear, the information of the following phase suggest the use of spear phishing or similar solutions,” Kaspersky stated in a new report.

The Russian cybersecurity company, which detected the assaults in Oct 2022, is tracking the action cluster less than the title “Lousy Magic.”

Attack chains entail the use of booby-trapped URLS pointing to a ZIP archive hosted on a malicious web server. The file, when opened, consists of a decoy doc and a malicious LNK file that culminates in the deployment of a backdoor named PowerMagic.

Written in PowerShell, PowerMagic establishes get in touch with with a remote server and executes arbitrary instructions, the benefits of which are exfiltrated to cloud expert services like Dropbox and Microsoft OneDrive.

PowerMagic also serves as a conduit to supply the CommonMagic framework, a established of executable modules that are developed to have out distinct responsibilities these types of as interacting with the command-and-manage (C2) server, encrypting and decrypting C2 targeted traffic, and executing plugins.

Two of the plugins discovered so much occur with capabilities to capture screenshots each 3 seconds and acquire files of curiosity from related USB gadgets.

Kaspersky explained it uncovered no proof linking the procedure and its tooling to any identified danger actor or group.

Identified this short article intriguing? Follow us on Twitter  and LinkedIn to read through extra special material we post.

Some parts of this article are sourced from:
thehackernews.com

Previous Post: « New ShellBot DDoS Malware Variants Targeting Poorly Managed Linux Servers
Next Post: Hackers Use NuGet Packages to Target .NET Developers »

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor
  • LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents
  • Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware
  • Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms
  • Are Forgotten AD Service Accounts Leaving You at Risk?

Copyright © 2025 · AllTech.News, All Rights Reserved.