Cyber Threat Report: 'TODDLERSHARK: ScreenConnect Vulnerability Exploited to Deploy BABYSHARK Variant'
Report Author | Kroll |
---|---|
Publication Date | 2024-03-05 |
Original Reporting | Source |
Related Intrusion Sets | Kimsuky |
Identified CVEs | CVE-2024-1709 , CVE-2024-1708 |
Blog post from Kroll which describes the exploitation of vulnerabilities in ConnectWise ScreenConnect to deploy TODDLERSHARK malware which the researchers say is a variant of the BABYSHARK VBScript based malware. BABYSHARK has previously been linked to Kimsuky, a North Korean intrusion set.
Cyber Threat Graph Context
Explore how this report relates to the wider threat graph