ReconShark

Description

(SentinelOne) The ability of ReconShark to exfiltrate valuable information, such as deployed detection mechanisms and hardware information, indicates that ReconShark is part of a Kimsuky-orchestrated reconnaissance operation that enables subsequent precision attacks, possibly involving malware specifically tailored to evade defenses and exploit platform weaknesses.

Names

Name
ReconShark

Category

Malware

Type

  • Reconnaissance

Information

Other Information

Uuid

b612f8bc-506d-4e5b-b78d-cba0b6a9b570

Last Card Change

2023-06-21