Worok

🔴 High
Also known as: Worok

Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBeat, and a C# loader named PNGLoad.

🌍 Country China
Risk Level High
🎯 Incident Type Espionage
Government Energy Company

Introduction

Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBeat, and a C# loader named PNGLoad.

Activities and Tactics

Targeted Sectors: Government, Energy Company

Country of Origin: 🇨🇳 China

Risk Level: High

Incident Type: Espionage

Suspected Victims: East Asia, Central Asia, Southeast Asia, The Middle East, Southern Africa

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • Backdoor.Oldrea
  • PowerDuke
  • POWERSTATS
  • Power Loader
  • POWERSOURCE
  • CyberGate
  • Cyber Eye RAT
  • PowerRAT
  • Proxy Shell:
  • CVE-2021-34523:

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

References pending cataloguing.