APT Group “ToddyCat” Exploits ESET Vulnerability to Silently Deploy Malware
135/68 Wednesday, April 9, 2025 Researchers have discovered that the APT group ToddyCat, suspected to be linked to China, is exploiting a now-patched vulnerability (CVE-2024-11859) in ESET antivirus software to stealthily load and execute malware on target systems. The vulnerability, fixed in January 2024, stems from insecure DLL search order handling, allowing attackers to trick […]