« 2016 »

31 reports

2016-12-08 • KRMND

South Korea’s Ministry of National Defense said malware was distributed through an internet antivirus relay server after attackers exploited weaknesses in the military internet antivirus system. Investigators found the same malware on some defense-network…

#News #DESERTWOLF
2016-12-05 • KRCERT

NixTech issued security updates for SafePC after a vulnerability allowed abuse of its file distribution feature for malware delivery and remote code execution. Affected products include SafePC Enterprise 3.5, 4.0, and 5.0, SafePrivacy 4.0 and 5.0, and Saf…

#SafePC
2016-11-18 • Sands Lab

malwares.com analyzed malicious Hangul Word Processor documents that exploited a vulnerability rather than relying on macros, allowing code execution when the document was opened in affected HWP versions. The embedded BinData area contained shellcode obfu…

2016-08-25 • Qihoo360

360’s report links the 2016 Bangladesh Central Bank theft and the attempted attacks on Vietnam’s Tien Phong Bank and other banks through shared focus on SWIFT operations and malware code commonality. The Bangladesh case involved fraudulent SWIFT transfer …

#APT-C-26
2016-07-28 • Hauri

Hauri analyzed malware used in the Interpark breach, where a shopping mall employee's PC was compromised through an email attachment sent under the guise of an acquaintance. The sample attempted to hide infection by launching a legitimate screensaver file…

#Interpark
2016-07-01 • NProtect

South Korean police attributed a February compromise of domestic conglomerate networks to North Korea, reporting that more than 130,000 computers were infected with the “Ghost Rat” malware. TachyonLab analyzed a sample named zegost.exe, describing it as a…

#GhostRAT
2016-06-17 • Kaspersky

Kaspersky linked Operation Daybreak to ScarCruft based on shared infrastructure and targeting, describing targeted attacks against more than two dozen high-profile victims across Asia, Europe, the Middle East, and the United States. The campaign used a pr…

#Scarcruft #Daybreak #CVE-2016-1010