« 2017 »

97 reports

2017-08-14 • Paloalto Networks

Unit 42 identified continued Blockbuster-linked attack activity targeting individuals associated with United States defense contractors. The campaign used weaponized Microsoft Office documents with malicious macros and decoys copied from defense-contracto…

#Blockbuster
2017-07-10 • Mcafee

The excerpt identifies a WannaCry outbreak technical overview and includes a long list of targeted file extensions, indicating ransomware-style file encryption behavior across documents, databases, source code, multimedia, archives, disk images, and offic…

#WannaCry #Slides
2017-07-10 • Intezer

Intezer analyzed WannaCry samples and found code-level overlaps with malware families associated in the report with North Korean hackers or attacks on South Korean organizations. The ransomware outbreak used EternalBlue to spread across Windows networks, …

#WannaCry
2017-06-15 • Recorded Future

Recorded Future frames North Korean cyber activity as consistent with the state's asymmetric military strategy and self-financing needs rather than irrational behavior. The report identifies the Reconnaissance General Bureau, and likely Bureau 121, as cen…

#Trend
2017-06-08 • Somansa

WannaCry spread worm-like across Windows hosts by probing SMB services for the MS17-010 remote code execution vulnerability and using SMB response values to decide whether a target was vulnerable or already compromised. The infection flow used SMB negotia…

#WannaCry
2017-05-31 • MITRE

MITRE ATT&CK’s Lazarus Group entry maps a broad set of observed behaviors across the actor also tracked as Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, Diamond Sleet, and related names. The excerpt describes credential and environment disco…

#G0032 #T1082 #T1090 #T1140 #T1005 #T1041 #T1560 #T1046 #T1083 #T1497 #T1036 #T1027 #T1567 #T1071 #T1124 #T1204 #T1057 #T1053 #T1566 #T1102 #T1059 #T1001 #T1105 #T1055 #T1620 #T1543 #T1489 #T1078 #T1008 #T1571 #T1218 #T1220 #T1588 #T1203 #T1189 #T1049 #T1574 #T1098 #T1087 #T1593 #T1589 #T1016 #T1587 #T1591 #T1585 #T1583 #T1557 #T1547 #T1614 #T1106 #T1573 #T1048 #T1562 #T1608 #T1070 #T1047 #T1074 #T1134 #T1056 #T1529 #T1010 #T1553 #T1033 #T1485 #T1012 #T1110 #T1534 #T1104 #T1202 #T1221 #T1132 #T1021 #T1561 #T1564 #T1584 #T0865 #T1542 #T1491
2017-05-30 • Group-IB

Group-IB attributes a shift in Lazarus operations from espionage and destructive attacks against South Korean and U.S. targets toward attacks on banks and financial institutions worldwide. The report details the Bangladesh Central Bank SWIFT theft attempt…

#Whitepaper #Lazarus