Disco

Malware Profile Updated 3 months ago
Download STIX
Preview STIX
DisCo is a malware that emerged as a significant threat in the cybersecurity landscape. It's a harmful program designed to exploit and damage computer systems, often infiltrating them without the user's knowledge through suspicious downloads, emails, or websites. Unlike conventional malicious software, DisCo optimizes a deep neural network (DNN) model for distributed training over multiple GPU machines, demonstrating an advanced level of sophistication. In 2020, it was discovered that a group had started using DisCo as a second implant, a simple dropper written in Go, specifically designed to exfiltrate data. The European Union has acknowledged the risk posed by such sophisticated malware like DisCo. As the DisCo post highlights, the EU Copyright Directive already provides a legal framework addressing the issue of training AI systems, which could potentially be exploited by such malware. The directive includes new copyright requirements added by Members of the European Parliament (MEPs) to the Commission’s original proposal, offering some degree of legal protection against these threats. Cybersecurity firm ESET believes that DisCo is used in conjunction with Attacks-in-the-Middle (AiTM), while another malware, NightClub, is employed for victims where traffic interception at the Internet Service Provider (ISP) level isn't possible due to measures like the use of end-to-end encrypted VPNs. This highlights the evolving strategies of cybercriminals and underscores the importance of robust cybersecurity measures, including legal technology and AI adoption, a cause championed by professionals like Anush Emelianova, Product Marketing Manager at DISCO.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
NightClub
3
The malware named "NightClub" is a malicious software framework primarily used by an entity known as MoustachedBouncer, according to cybersecurity firm ESET. This framework was so named due to the presence of a C++ class called 'nightclub' within its code. ESET has identified that NightClub is typic
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Implant
Windows
Eset
AITM
Dropper
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
StrongPityUnspecified
1
StrongPity is a malicious software (malware) that infiltrates computer systems, typically through suspicious downloads, emails, or websites. The malware has been active for over a decade and is possibly linked to the Turkish government. It's designed to exploit and damage systems, steal personal inf
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
RgbUnspecified
1
RGB, a threat actor with ties to North Korea, has been involved in a range of malicious cyber activities. The group was designated by the Office of Foreign Assets Control (OFAC) on January 2, 2015, under Executive Order 13687 for being a controlled entity of the North Korean government. In addition
TurlaUnspecified
1
Turla, also known as Pensive Ursa, is a sophisticated threat actor linked to Russia that has been active for many years. The group is known for its advanced cyber-espionage capabilities and has been associated with numerous high-profile breaches. According to the MITRE ATT&CK and MITRE Ingenuity dat
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Disco Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
CERT-EU
5 months ago
AI and Cybersecurity: A Rob Burgundy Investigation | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
5 months ago
Hackaday Podcast Episode 261: Rickroll Toothbrush, Keyboard Cat, Zombie Dialup
CERT-EU
5 months ago
AI and Cybersecurity: A Rob Burgundy Investigation
CERT-EU
9 months ago
Techrights — Links 27/10/2023: Facebook Shrinks by a Lot, Yet More Microsoft Layoffs
CERT-EU
9 months ago
Techrights — Links 21/10/2023: Fakecoin Prosecutions and Growing Tensions Near China
CERT-EU
a year ago
How AI can evolve and up-level your firm's cyber defense strategy
CERT-EU
a year ago
New Cyber Threat 'MoustachedBouncer' Targets Embassies in Belarus
CERT-EU
9 months ago
Search | arXiv e-print repository
BankInfoSecurity
a year ago
Breach Roundup: Raccoon Stealer Makes a Comeback
DARKReading
a year ago
'MoustachedBouncer' APT Spies on Embassies, Likely via ISPs
CERT-EU
a year ago
Let me take you down... to Liverpool for Eurovision
CERT-EU
10 months ago
Search | arXiv e-print repository
CERT-EU
a year ago
Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say