Uptime Hamster: 10d 6h 42mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Worok

Worok

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: Proxy Shell, CVE-2021-34523
Ver en IntelTracker → APTTrail →
Worok is a cyber espionage group that first emerged in late 2020, focusing on high-profile entities predominantly across Asia, Africa, and the Middle East. The group's primary motivation is information theft and intellectual property acquisition. Worok distinguishes itself through its consistent development and deployment of custom tools, notably utilizing steganography to conceal malicious payloads within seemingly innocuous image files, a tactic that aids in evading detection. While there are some observed commonalities with the China-linked TA428 group, such as activity times and targeted verticals, researchers assess these links with low confidence, indicating Worok is likely a distinct entity.

Aliases del actor

Proxy ShellCVE-2021-34523

Actores similares

entryshellactor · 1cve-2023-41991actor · 1goreshellactor · 1cve-2023-36884actor · 1PowerShell Profileactor · 1CS FQL: 26. Detect and Decode Base64-Encoded PowerShell Commands - httpactor · 1shell-crewactor · 1tortoiseshellactor · 1zxshellactor · 1Tortoiseshellapt · 0
Motivacion