Cyber Threat Report: 'TODDLERSHARK: ScreenConnect Vulnerability Exploited to Deploy BABYSHARK Variant'

Report Author Kroll
Publication Date 2024-03-05
Original Reporting Source
Related Intrusion Sets Kimsuky
Identified CVEs CVE-2024-1709 , CVE-2024-1708

Blog post from Kroll which describes the exploitation of vulnerabilities in ConnectWise ScreenConnect to deploy TODDLERSHARK malware which the researchers say is a variant of the BABYSHARK VBScript based malware. BABYSHARK has previously been linked to Kimsuky, a North Korean intrusion set.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1027.010 Command Obfuscation Defense Evasion
T1059.003 Windows Command Shell Execution
T1053.005 Scheduled Task Execution, Persistence, Privilege Escalation
T1218.005 Mshta Defense Evasion
T1132.001 Standard Encoding Command and Control