Spyke

Correct me if I'm wrong, but this doesn't look like this has anything to do with Syncthing vulnerabilities. Instead it looks like a hack that uses a preconfigured Syncthing installation to transfer sensitive data. Disturbing nonetheless.

102
Holzkohlenreply
feddit.de

Bet they also utilize electricity these bastards! What's next? Physics? Oh the humanity!

12

Just like using a remote desktop tool in a scam I suppose

10
treadfulreply
lemmy.zip

Looks like a specially modified SyncThing was just used for exfil.

5

The article uses the word modified, but it sounds like it's just talking about configuring it and using it as normal.

18
feddit.it

The attack begins with a phishing email sent to the target

Okay bro im not reading past this its 2024

79
lemmy.ml

Please dont link with a Google Amp link.

63

It's a convenient file transfer/sync tool. Copying data has to happen somehow, I'm not surprised someone thought to use syncthing for that purpose >.<, since it can do that. But its not really different than any other tool here.

5

You reached the end

Ukraine says hackers abuse SyncThing tool to steal data | Spyke