{"id":3862,"date":"2021-10-16T21:08:55","date_gmt":"2021-10-17T02:08:55","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3862"},"modified":"2021-10-16T21:08:56","modified_gmt":"2021-10-17T02:08:56","slug":"darkhalo-could-still-be-active","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/","title":{"rendered":"DarkHalo could still be active"},"content":{"rendered":"\n<p>In December of last year the media covered the Sunburst security incident. Advanced persistent threat actor (APT) DarkHalo had compromised a widely used enterprise software provider and used its infrastructure for a long time to distribute spyware under the guise of legitimate software updates. However, after the media hype and an intensive search from the security community, DarkHalo seemed to have either made himself invisible or disconnected but&#8230;<\/p>\n\n\n\n<p>Kaspersky says the threat may still be latent. Its Global Research and Analysis Team (GReAT) found last June traces of a successful DNS hijacking attack against several government organizations in the same country. In the case accessed by the Russian company, the targets of the attack were trying to access the web interface of a corporate email service, but were redirected to a fake copy of that web interface and then tricked into downloading a malicious software update.<\/p>\n\n\n\n<p>Kaspersky were the ones who recovered the &#8216;update&#8217; from these attacks and discovered that it deployed a previously unknown backdoor, now known as Tomiris. This backdoor would have the objective of entering the attacked system and downloading other malicious components. Kaspesrsky noticed how the Tomiris backdoor looked suspiciously similar to Sunshuttle, the malware deployed in the Sunburst attack.<\/p>\n\n\n\n<p>The company has found several striking similarities. Like Sunshuttle, Tomiris had been developed in the Go programming language. Both are based on scheduled tasks for persistence, use randomness and delays to hide their activities and have a very similar workflow, moreover, Tomiris also shows some English errors in its strings, which leads to think that it has not been created by people who speak this language natively. <\/p>\n\n\n\n<p>Finally, the Tomiris backdoor was discovered on networks where other machines were infected with Kazuar, a backdoor known for its Sunburst backdoor code overlaps. The best we can deal with these situations is to take security measures and also remember that this threat targets companies and that is why it is even more important to take security measures on their part.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In December of last year the media covered the Sunburst security incident. Advanced persistent threat actor (APT) DarkHalo had compromised a widely used enterprise software provider and used its infrastructure for a long time to distribute spyware under the guise of legitimate software updates. However, after the media hype and an intensive search from the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3864,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DarkHalo could still be active - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DarkHalo could still be active - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-17T02:08:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-10-17T02:08:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"728\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"DarkHalo could still be active\",\"datePublished\":\"2021-10-17T02:08:55+00:00\",\"dateModified\":\"2021-10-17T02:08:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/\"},\"wordCount\":337,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/DarkHalo.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/\",\"name\":\"DarkHalo could still be active - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/DarkHalo.jpg\",\"datePublished\":\"2021-10-17T02:08:55+00:00\",\"dateModified\":\"2021-10-17T02:08:56+00:00\",\"description\":\"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/DarkHalo.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/DarkHalo.jpg\",\"width\":728,\"height\":380},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkhalo-could-still-be-active\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DarkHalo could still be active\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DarkHalo could still be active - Truxgo Server Blog","description":"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/","og_locale":"es_MX","og_type":"article","og_title":"DarkHalo could still be active - Truxgo Server Blog","og_description":"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........","og_url":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-10-17T02:08:55+00:00","article_modified_time":"2021-10-17T02:08:56+00:00","og_image":[{"width":728,"height":380,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"DarkHalo could still be active","datePublished":"2021-10-17T02:08:55+00:00","dateModified":"2021-10-17T02:08:56+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/"},"wordCount":337,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/","url":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/","name":"DarkHalo could still be active - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg","datePublished":"2021-10-17T02:08:55+00:00","dateModified":"2021-10-17T02:08:56+00:00","description":"You may remember DarkHalo for the Sunburst security incident last year and it seems that these actors may still be active........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/DarkHalo.jpg","width":728,"height":380},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/darkhalo-could-still-be-active\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DarkHalo could still be active"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3862"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3862\/revisions"}],"predecessor-version":[{"id":3865,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3862\/revisions\/3865"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3864"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}