« 2017 »

97 reports

2017-10-13 • KRCERT

KISA’s WannaCry material outlines the incident timeline, infection spread, domestic response, and observable infection symptoms. The technical sections focus on WannaCry’s components, operating logic, and exploitation of the SMB vulnerability CVE-2017-014…

#WannaCry
2017-10-12 • Ahnlab

AhnLab analyzes Operation Bitter Biscuit as a long-running APT campaign observed from 2011 through 2017 against major South Korean organizations, with additional earlier activity affecting Japan, India, and possibly Russian-language users. The campaign us…

#BitterBiscuit
2017-10-10 • Intezer

Intezer found that WannaCry and Joanap samples associated in the report with North Korean activity shared an encryption implementation that also appeared in Magic Hound malware. The shared code was traced to a 2002 CodeProject example, suggesting the over…

2017-09-18 • Sands Lab

The Korean malware analysis excerpt describes a document-based infection involving embedded EPS/PostScript content and GhostScript. The extracted artifact creates a startup-path executable named SMHost.exe under the Windows roaming profile, indicating per…

2017-09-11 • Fireeye

Mandiant reported suspected North Korean actors targeting South Korean cryptocurrency exchanges in 2017 as part of a broader shift from traditional espionage toward financially motivated cyber operations. The observed activity included spearphishing again…

#Cryptocurrency
2017-08-31 • Hauri

Hauri reported a targeted malware campaign aimed at a university political science professor using a lure document tailored to the recipient. The attacker sent a large-file transfer link rather than a normal attachment, causing the victim to download a ma…

2017-08-23 • USCISA

US-CERT analyzed three files associated with DeltaCharlie attack malware that combine backdoor command-and-control capability with DDoS attack functions. One Windows executable installs a packet driver and a service named netplug, uses the mutex \Global\N…

#DeltaCharlie
2017-08-15 • Fortinet

FortiGuard Labs analyzed a new KONNI RAT variant delivered by a malicious Word document using a decoy article about North Korea, while noting that the actual victim relationship to North Korea was unclear. The document’s VB macro drops an Aspack-packed in…

#Konni