« 2019 »

183 reports

2019-02-12 • emptyregisters

The Lazarus downloader analysis builds on previously identified January 2019 samples and derives a YARA detection for a related payload. Sandbox behavior showed the malware beaconing to a control server with an HTTP request for an info.asp path, providing…

#Lazarus
2019-02-09 • 이도

A Korean Android app developer described a compromise in which an attacker took over the developer's Google account, accessed Bitbucket through that login, and obtained source code. The attacker was able to distribute a malicious APK because the Android S…

#Mobile #MalBus
2019-01-31 • VNCERT

VNCERT warned in late July 2018 that targeted malware attacks had been observed against information systems at several Vietnamese banks and national critical-infrastructure organizations. On 23 July 2018, the center issued coordination warning 234/VNCERT-…

2019-01-30 • Cisco Talos

Cisco Talos observed a targeted malware campaign using a Microsoft Word document disguised as a Cisco Korea job posting. The lure reused legitimate job-posting content and appeared to start a multi-stage infection process aimed at specific organizations. …

2019-01-29 • MITRE

MITRE ATT&CK profiles APT38, also tracked as NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, and Group G0082. The entry describes financially motivated North Korea-linked activity including fake financial or ventu…

#APT38 #G0082 #T1082 #T1005 #T1112 #T1115 #T1083 #T1027 #T1071 #T1204 #T1057 #T1053 #T1566 #T1059 #T1105 #T1543 #T1486 #T1135 #T1218 #T1588 #T1189 #T1049 #T1217 #T1106 #T1562 #T1070 #T1056 #T1529 #T1569 #T1033 #T1485 #T1110 #T1518 #T1561 #T1565 #T1505
2019-01-22 • Norfolk

The source analyzes PSLogger, a keylogging and screen-grabbing utility connected to attempted intrusions against financial organizations in Vietnam. Two observed versions include a DLL injected through a modified PowerSploit framework and a standalone exe…

#PSLogger #Lazarus