« 2018 »

171 reports

2018-10-18 • Mcafee

McAfee Advanced Threat Research describes Operation Oceansalt as five adapted attack waves against victims primarily in South Korea, with additional activity in the United States and Canada. The malware reused large portions of code from the older Seasalt…

#Oceansalt
2018-10-04 • Hauri

Hauri analyzed resume-themed malicious Hangul Word Processor documents used in Korean-targeted spear-phishing campaigns, noting similarities to activity publicly associated with groups such as BlueNoroff, APT37, ScarCruft, RedEyes, Group123, and Geumsong1…

2018-10-03 • Fireeye

FireEye profiles APT38 as a financially motivated North Korean regime backed group specializing in bank intrusions and destructive operations. The report says the group has attempted to steal more than $1.1 billion, compromised more than 16 organizations …

#APT38 #NACHOCHEESE #KEYLIME #QUICKRIDE
2018-10-03 • Intezer

Intezer linked Final1stspy activity to APT37/Group123 by analyzing code reuse across NOKKI, KONNI, KimJongRAT, DOGCALL/ROKRAT, and FreeMilk-related samples. The reported NOKKI-associated malicious document used VBScript to download Final1stspy, whose `Loa…

#APT37 #FreeMilk
2018-10-02 • Igloo

Igloo analyzes a collected HIDDEN COBRA java.exe malware sample that connects to hardcoded command-and-control servers and executes attacker commands when a connection succeeds. The sample is reported to be created by a 64-bit malicious DLL and stores req…

#HiddenCobra
2018-10-02 • USCISA

U.S. government agencies attributed the FASTCash ATM cash-out campaign to HIDDEN COBRA, describing North Korean government activity against banks in Africa and Asia since at least late 2016. The campaign compromised retail payment switch application serve…

#FASTCash #HiddenCobra
2018-10-01 • kino

A suspicious HWP/OLE file contained shellcode that decoded an embedded payload and downloaded additional malware from a server at 211.218.126.236. The downloaded component was identified as a hwdoor downloader that saved svrc.exe under a temporary path an…

#hwdoor
2018-09-28 • Intezer

Intezer's North Korea Cyber Campaign Timeline presents code-reuse analysis across malware and cyber campaigns affiliated with North Korea from 2007 through 2018. The source frames the timeline as a way to inspect named attacks by campaign name and first-o…

#Trend