Summary:
High-profile companies and local governments located primarily in Asia are the subjects of targeted attacks by a previously undocumented espionage group dubbed Worok. Worok is a cyber espionage group that develops its own tools, as well as leveraging existing tools, to compromise its targets. Worok's toolset includes a C++ loader CLRLoad, a PowerShell backdoor PowHeartBeat, and a C# loader PNGLoad that uses steganography to extract hidden malicious payloads from PNG files. Worok is said to share overlaps in tools and interests with another adversarial collective tracked as TA428, with the group linked to attacks against entities spanning energy, financial, maritime, and telecom sectors in Asia as well as a government agency in the Middle East and a private firm in southern Africa.[/subscribe_to_unlock_form]
Summary:
High-profile companies and local governments located primarily in Asia are the subjects of targeted attacks by a previously undocumented espionage group dubbed Worok. Worok is a cyber espionage group that develops its own tools, as well as leveraging existing tools, to compromise its targets. Worok's toolset includes a C++ loader CLRLoad, a PowerShell backdoor PowHeartBeat, and a C# loader PNGLoad that uses steganography to extract hidden malicious payloads from PNG files. Worok is said to share overlaps in tools and interests with another adversarial collective tracked as TA428, with the group linked to attacks against entities spanning energy, financial, maritime, and telecom sectors in Asia as well as a government agency in the Middle East and a private firm in southern Africa.[emaillocker id="1283"]

References:
The following reports contain further technical details:
https://thehackernews.com/2022/09/worok-hackers-target-high-profile-asian.html
https://www.welivesecurity.com/2022/09/06/worok-big-picture/
[/emaillocker]