#TODDLERSHARK

Malware/Tool

2024-03-05 • TODDLERSHARK: ScreenConnect Vulnerability Exploited to Deploy BABYSHARK Variant

TODDLERSHARK is an obfuscated Windows malware variant resembling BABYSHARK and associated with Kimsuky. It was deployed in an attempted compromise beginning with exploitation of critical ConnectWise ScreenConnect vulnerabilities, including the CVE-2024-1709 authentication bypass. The chain used the legitimate mshta.exe binary to execute heavily obfuscated VBScript containing randomized function and variable names, hexadecimal content, and junk code. The malware modified VBAWarnings registry settings, created a scheduled task that ran malicious code every minute for persistence, and periodically collected system information. It encoded collected data inside Privacy-Enhanced Mail certificate material before exfiltrating it to attacker command-and-control infrastructure. Kroll observed and stopped the attempted compromise, while the second report describes related Kimsuky targeting of governments, research centers, universities, and think tanks.

Tagged Reports

« Back