« 2016 »

31 reports

2016-06-01 • Hauri

Hauri analyzes custom malware used in the Bangladesh Bank SWIFT theft, in which more than $100 million held at the U.S. Federal Reserve was illicitly withdrawn. The report says the malware was built for the targeted institution: it used Bangladesh Bank SW…

#BangSwift
2016-05-13 • Bae Systems

BAE Systems traced SWIFT-targeting bank malware into a wider campaign by identifying a unique file wipe-out function shared across samples tied to the Vietnam bank case and a newly found bot. The analyzed sample installed itself as a Windows service, used…

#BangSwift
2016-04-25 • Bae Systems

BAE Systems analyzed custom malware linked to the Bangladesh Bank SWIFT heist, where attackers attempted to transfer $951 million and $81 million remained unaccounted for. The malware was built for an environment running SWIFT Alliance Access with an Orac…

#BangSwift
2016-03-08 • Qihoo360

Qihoo 360 described Operation OnionDog as a multi-year campaign observed from at least 2013 to 2015 against government entities, transportation companies, and energy industries, while stating it had not found a connection to Lazarus at that time. The acti…

#OnionDog
2016-02-24 • Hauri

The excerpt analyzes a backdoor that receives command codes from a C&C server and can download and execute additional malware, run CMD commands, and control the infected PC. It persists by copying itself into a specific folder, generating a random service…

#INITROY
2016-02-24 • Novetta

Novetta Operation Blockbuster documents Lazarus Group remote administration and content staging malware families uncovered during a broader industry investigation. The report explains the Romeo RAT families, Sierra spreaders, Joanap peer to peer staging c…

#Whitepaper #Blockbuster #Lazarus
2016-02-24 • Kaspersky

Kaspersky describes Operation Blockbuster research linking malware used in the Sony Pictures attack to a wider Lazarus Group cluster spanning activity back to at least 2009. The report connects campaigns and malware families including Operation Troy, Dark…

#Blockbuster #Lazarus
2016-02-23 • Sands Lab

A leaked digital certificate from a security vendor was abused to sign malware, exploiting trust in software used by financial institutions and public-sector organizations. The signed executable is described as a downloader that contacted an external serv…

#INITROY
2016-02-04 • Crowd Strike

CrowdStrike’s 2015 Global Threat Report assessed that DPRK-linked activity in 2015 shifted toward espionage rather than destructive operations, with most observed malware directed at Republic of Korea targets during periods of heightened inter-Korean tens…

#Trend #Chollima