Chinese hacker group Earth Longzhi resurfaces with more advanced malware tactics

by

in
Chinese hacker group Earth Longzhi resurfaces with more advanced malware tactics

This is not the first time that Earth Longzhi has leveraged the BYOVD technique, and its attacks against organizations in East and Southeast Asia and Ukraine date back to November 2022.

According to the company’s research, earth longzhi remains active and continues to improve its tactics, techniques, and procedures.

Back in November 2022, security researchers Ted Lee and Hara Hiroaki published a detailed description of the exploits they’ve deployed using the RTCore64.sys driver to restrict the execution of security products.

If the stack size is too large, the driver will trigger a stack overflow exception and terminate the current process.

What’s more, the payload is installed as a kernel-level service using Remote Procedure Call (RPC) instead of Windows APIs to evade detection.

#shorts #techshorts #technews #tech #technology #Earth Longzhi #security products #Trend Micro

๐Ÿ‘‹ Feeling the vibes?

Keep the good energy going by checking out my Amazon affiliate link for some cool finds! ๐Ÿ›๏ธ

If not, consider contributing to my caffeine supply at Buy Me a Coffee โ˜•๏ธ.

Your clicks = cosmic support for more awesome content! ๐Ÿš€๐ŸŒˆ


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *