« 2017 »

97 reports

2017-11-28 • Cisco Talos

Talos identified a November 2017 ROKRAT variant delivered through a malicious HWP document themed around a South Korean North Korean human rights and reunification group. The document dropped a ROKRAT loader as HncModuleUpdate.exe, decoded an embedded pay…

#RokRAT
2017-11-20 • Paloalto Networks

Unit 42 identified a mobile-focused malware cluster tied by code, mutex, and infrastructure overlaps to Operation Blockbuster activity, with targeting evidence pointing to Korean language speakers using Samsung devices. A Windows PE server named JAVAC.EXE…

#Blockbuster #Mobile
2017-11-14 • Bloo

Volgmer is a Windows backdoor attributed in the source to North Korea's Lazarus Group, also known as Hidden Cobra, and described as active from at least 2013-2014 through later campaigns. It installs as a legitimate-looking service with a random name, sto…

#Volgmer #Lazarus #T1082 #T1059.003 #T1005 #T1041 #T1071.001 #T1112 #T1518.001 #T1566.001 #T1001.003 #T1105 #T1571 #T1049 #T1016 #T1036.004 #T1070.006 #T1573 #T1055.001 #T1569.002 #T1543.003 #T1027.001
2017-11-10 • spuz

The excerpt describes North Korea’s Kwangmyong intranet as an internally accessible network paired with Red Star OS and the Naenara browser, with access restricted to users inside the country. It notes that Naenara reaches an internal address at 10.76.1.1…

#OpSec
2017-10-27 • Nao

WannaCry disrupted NHS services in England from 12 to 19 May 2017 after a global ransomware outbreak affected more than 200,000 computers in at least 100 countries. NHS England said at least 80 of 236 trusts were infected or disrupted by precautionary shu…

#WannaCry