« 2018 »

171 reports

2018-01-29 • Erratasec

Errata Security critiques the U.S. government’s public attribution of WannaCry to North Korea, arguing that the evidence and policy framing left key attribution questions unresolved. The article distinguishes North Korea as a state from external hacking a…

#WannaCry
2018-01-25 • Ahnlab

AhnLab analyzed attacks abusing central management systems used by organizations to distribute policies and files to internal endpoint agents. The excerpt describes two main intrusion paths: stealing or abusing management-server administrator access to pu…

2018-01-23 • Thestar

Metrolinx confirmed that a cyberattack traced to a North Korean source breached a firewall but affected a system not tied to customer data, employee data, or safety systems. The transit agency said its joint security operation with the province detected a…

#News #Metrolinx
2018-01-23 • Ahnlab

AhnLab analyzed a Windows Script File received from a customer that behaved like an APT delivery chain by displaying a decoy Korean HWP document while downloading and executing a malicious DLL. The WSF file embedded a normal HWP file, fetched a password-p…

#akdoor
2018-01-16 • Cisco Talos

Talos links six 2017-to-early-2018 campaigns to Group 123, with shared code and PDB artifacts tying activity such as Golden Time, Evil New Year, North Korean Human Rights, FreeMilk, and Are You Happy? together. Several campaigns targeted South Korean user…

#RokRAT #Group123