« 2018 »

171 reports

2018-12-23 • Cyberfox

The analysis examines a malicious Word document macro that the author says was associated with Lazarus tooling by archive context and flagged by Thor's APT_MalDoc_SharpShooter_Lazarus_Campaign_Dec18_1 YARA rule. The macro was slightly obfuscated and defin…

#APT38
2018-12-13 • Mcafee

McAfee documented Operation Sharpshooter, a global campaign against nuclear, defense, energy, financial, defense, and government related organizations. Malicious job description documents with Korean-language metadata used macros and embedded shellcode to…

#Sharpshooter #RisingSun
2018-12-12 • fboldewin

Hidden Cobra, also known as Lazarus or APT38, is tied in the PDF to FASTCash activity against banking payment-switch infrastructure. The recovered analysis describes a 2018 incident where attackers manipulated transaction response messages on an IBM AIX P…

#FASTCash
2018-12-10 • Fireeye

FireEye and Mandiant researchers introduce APT38 as a North Korea-linked financial intrusion group that operates separately from ordinary espionage clusters. The talk explains how the group targets banks and financial infrastructure, combines long dwell t…

#APT38 #Youtube
2018-12-05 • Arbornetworks

NETSCOUT ASERT described STOLEN PENCIL as an APT campaign, possibly originating from DPRK, that had targeted academic institutions since at least May 2018. Victims received spear-phishing emails linking to actor-controlled sites that displayed lure docume…

#STOLENPENCIL
2018-11-24 • kino

A malicious HWP document themed as a National Security Council Policy Advisory Committee plenary meeting plan was found after likely use in attacks, with metadata showing author and last-saved values of yoonjh337 and cha0520. The document contains an embe…