Worok
Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBeat, and a C# loader named PNGLoad.
Worok is a China-based nation-state cyber espionage group primarily targeting government and energy sectors.
Worok is a China-based nation-state cyber espionage group. Its targets include government and energy company entities primarily in East Asia, Central Asia, Southeast Asia, the Middle East, and Southern Africa. The group's key TTPs involve a C++ loader (CLRLoad), a PowerShell backdoor (PowHeartBeat), and a C# loader (PNGLoad). Defenders should focus on monitoring PowerShell activity and detecting the execution of unknown C++/C# loaders.
Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBeat, and a C# loader named PNGLoad.
The Worok group primarily targets government entities and energy companies.
The main tools used by the Worok group include a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBeat, and a C# loader named PNGLoad.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.