A North Korean hacking group is attacking ScreenConnect flaws to drop dangerous new malware

North Korean state-sponsored threat actors were observed using the recently discovered ScreenConnect vulnerabilities to steal sensitive data from their targets.

A new report from Kroll, shared with Ny Breaking, shows that a group known as Kimsuky (AKA Thallium) exploited two flaws in ConnectWise’s solution to drop ToddleShark, an improved version of the company’s other backdoors. group, BabyShark and ReconShark.