« 2018 »

171 reports

2018-03-23 • FSI

The Black Hat presentation links Lazarus, Bluenoroff, Andariel, and Reaper/APT37 to financially motivated and espionage-focused attacks against banks, cryptocurrency exchanges, ATM operators, defense, government, and South Korean users. It describes a Mar…

#Andariel
2018-03-22 • SKShildus

The excerpt reviews several high-risk intrusion cases that had initially appeared to be separate incidents but were later assessed as the work of the same attacker. It says the actor found remaining vulnerabilities inside companies, penetrated internal en…

2018-03-22 • SKShildus

The excerpt analyzes malware used in multiple corporate intrusions and says variants built around June and August 2017 reused code, encoded internal data, and shared routines for collecting host information. The malware gathered items such as OS, IP addre…

2018-03-05 • Ahnlab

AhnLab analyzed 135 malicious Hangul Word Processor documents collected from September 2016 through December 2017 and found that North Korea-related workers and cryptocurrency-related workers were major targets. The DPRK-relevant activity includes Group A…

#RedEyes
2018-02-27 • Kaspersky

Kaspersky's 2018 Kimsuky presentation tracks the group's return in the 2016 to 2017 Fairy Tale activity against South Korean companies, government targets, and individuals. The deck describes a GoldDragon-centered malware cluster that collects system info…

#Kimsuky #Slides
2018-02-27 • Carbonblack

Carbon Black examined ROKRAT, also known as DOGcall, a remote access trojan used by attackers originating from North Korea. The malware is commonly delivered by loaders or carrier files such as macro-enabled Office documents, injects shellcode into proces…

#RokRAT