216.73.216.233

NGC4020 Attacks: DameWare Mini Remote Control Vulnerability

· Published 31/01/2025 09:54 · Modified 31/01/2025 11:06

Export JSON

Essential information

Published
31/01/2025 09:54
Modified
31/01/2025 11:06
Tags
2025-01-31 antivirus bypass dameware quasarrat reverse shell vulnerability
Related entities
1 intrusion sets (apt), 17 techniques (mitre), 2 malware, 2 others

Description

The Solar 4RAYS team investigated a cyberattack on an industrial company, uncovering that attackers exploited a in Mini Remote Control to deliver malware and disable security protections. The NGC4020 group initially compromised systems in December 2022 using CVE-2019-3980. They deployed Java-based reverse shells, , and custom malware to disable antivirus software. The attackers used a stolen expired code-signing certificate to load a malicious kernel driver. While they successfully disabled security controls, an error in task creation prevented further attack progression. The report provides technical details on the malware components and evasion techniques used.

External references