WailingCrab Malware Exploits Shipping-Themed Emails and MQTT Messaging Protocol

1 min read
Source: The Hacker News
WailingCrab Malware Exploits Shipping-Themed Emails and MQTT Messaging Protocol
Photo: The Hacker News
TL;DR Summary

A new malware loader called WailingCrab, also known as WikiLoader, is being spread through delivery- and shipping-themed emails. The malware, created by threat actor TA544, is split into multiple components and incorporates features to prioritize stealth and resist analysis. It uses legitimate hacked websites and platforms like Discord for command-and-control communications. The latest version of WailingCrab uses the MQTT protocol for communication and has removed the reliance on Discord for payload retrieval, increasing its stealthiness. Discord plans to switch to temporary file links to combat the abuse of its content delivery network for malware distribution.

Share this article

Reading Insights

Total Reads

0

Unique Readers

11

Time Saved

2 min

vs 3 min read

Condensed

83%

55195 words

Want the full story? Read the original article

Read on The Hacker News