WailingCrab Malware Exploits Shipping-Themed Emails and MQTT Messaging Protocol

A new malware loader called WailingCrab, also known as WikiLoader, is being spread through delivery- and shipping-themed emails. The malware, created by threat actor TA544, is split into multiple components and incorporates features to prioritize stealth and resist analysis. It uses legitimate hacked websites and platforms like Discord for command-and-control communications. The latest version of WailingCrab uses the MQTT protocol for communication and has removed the reliance on Discord for payload retrieval, increasing its stealthiness. Discord plans to switch to temporary file links to combat the abuse of its content delivery network for malware distribution.
Reading Insights
0
11
2 min
vs 3 min read
83%
551 → 95 words
Want the full story? Read the original article
Read on The Hacker News