« 2017 »

97 reports

2017-05-03 • Cisco Talos

KONNI campaigns observed from 2014 to 2017 used spear-phishing attachments and social engineering to make victims open .scr droppers that displayed decoy documents before executing malware. The malware evolved from a one-time information stealer into a mu…

#Konni
2017-04-07 • Paloalto Networks

Unit 42 links newly observed malicious Word documents and payloads targeting Korean-speaking individuals to Lazarus activity previously described in Operation Blockbuster. The documents likely arrived through spear phishing, used Korean decoy content, and…

#Blockbuster #Lazarus
2017-04-03 • Cisco Talos

ROKRAT was delivered through spear-phishing emails carrying malicious HWP documents themed around Korean reunification and North Korea, including one sent through a compromised Yonsei University mail server. The documents embedded EPS objects exploiting C…

#RokRAT
2017-04-03 • Kaspersky

Kaspersky links Lazarus and its Bluenoroff subgroup to financial-sector intrusions, including watering-hole attacks against banks and activity connected to SWIFT-related theft operations. Bluenoroff is described as focusing on financial gain, targeting ba…

#Bluenoroff #BangSwift
2017-04-03 • Kaspersky

Kaspersky links tools used against SWIFT-supporting banking systems to Lazarus Group’s broader lateral-movement arsenal based on forensic investigations at banks in two countries. The report separates Bluenoroff as a financially focused Lazarus unit that …

#Whitepaper #Bluenoroff #BangSwift
2017-04-01 • Symantec

Symantec's 2017 Internet Security Threat Report excerpt provides broad 2016 threat-trend context rather than usable Appleworm-specific evidence. It highlights targeted attacks, financial cybercrime, ransomware, exploit kits, IoT botnets, mobile threats, c…

#Appleworm
2017-02-23 • Cisco Talos

Talos analyzes a Korean HWP malicious document themed around analysis of North Korea's 2017 New Year address and apparently impersonating South Korea's Ministry of Unification. The document embedded OLE objects that dropped PE files when users clicked lin…

2017-02-20 • Bae Systems

BAE Systems analyzed malware and watering-hole infrastructure tied to a wave of bank attacks that earlier reporting had linked to the Lazarus threat actor. The examined samples included an encrypted backdoor loaded by a DLL, decrypted with XOR and RC4 rou…

#Lazarus