« 2018 »

171 reports

2018-11-06 • ESET

Attackers compromised StatCounter's web analytics script and used the trusted counter.js inclusion to target Gate.io's Bitcoin withdrawal page. The injected JavaScript checked for the /myaccount/withdraw/BTC URI, loaded a second-stage script from the look…

#Gateio
2018-11-01 • Somansa

SomanSA analyzed an October 2018 Lazarus APT operation against specific South Korean targets that used emails impersonating a lawyer and attached a malicious HWP document disguised as a normal file. The HWP contained a malicious PostScript component with …

#BattleCruiser #Lazarus
2018-10-31 • Intezer

Intezer traces part of Lazarus malware lineage to CasperPhpTrojan, an open-source RAT published on a Chinese project site, after VirusTotal samples from 2016 matched Lazarus-related code signatures. The analysis found overlap with RedGambler code genes, a…

#Lazarus
2018-10-24 • kino

The excerpt describes a malicious HWP/EPS document saved in October 2018 that used shellcode encoded with a 16-byte XOR key to download additional payloads. The delivery chain retrieved follow-on malicious code from WordPress plugin-themed paths on flydas…

#Manuscrypt
2018-10-23 • Tradeio

trade.io detailed its plan to fork TIO into Trade Token X after a contained security breach involving TIO tokens traded across multiple exchanges. The company set a snapshot time aligned with KuCoin’s closure of deposits and withdrawals, then used that sn…

#Tradeio