« 2017 »

97 reports

2017-12-27 • Hauri

KakaoTalk phishing was being used in South Korea to target North Korean defectors by impersonating a familiar contact and persuading victims to open a URL or install an app package. The malicious app masqueraded as “North Korea Prayer” and, once installed…

#Mobile
2017-12-21 • USCISA

DHS and the FBI analyzed seven malicious Windows executables attributed to HIDDEN COBRA activity and identified them as BANKSHOT malware variants. Five samples function as proxy applications that mask operator traffic with a shared cipher, while two are R…

#YARA #HiddenCobra #Bankshot
2017-12-21 • USCISA

DHS and the FBI identified BANKSHOT Trojan malware variants as tools used by the North Korean government. The advisory frames this activity under the U.S. Government name HIDDEN COBRA and points defenders to the related malware analysis report for technic…

#HiddenCobra