Ukraine says hackers abuse SyncThing tool to steal data

Queue@lemmy.blahaj.zone to Technology@lemmy.world – 129 points –
Ukraine says hackers abuse SyncThing tool to steal data
bleepingcomputer.com
27

You are viewing a single comment

Correct me if I'm wrong, but this doesn't look like this has anything to do with Syncthing vulnerabilities. Instead it looks like a hack that uses a preconfigured Syncthing installation to transfer sensitive data. Disturbing nonetheless.

It's a Phishing scam using a tool. It's no more exploiting SyncThing than TCP/IP.

Just like using a remote desktop tool in a scam I suppose

Looks like a specially modified SyncThing was just used for exfil.

The article uses the word modified, but it sounds like it's just talking about configuring it and using it as normal.