« 2019 »

183 reports

2019-01-13 • Norfolk

An attempted intrusion against Chilean interbank network Redbanc used a fake LinkedIn developer-job approach to persuade an employee to run ApplicationPDF.exe. The .NET downloader displayed a fake job application form while contacting a C2 server, writing…

#Lazarus
2019-01-08 • Malwarebytes

Ryuk ransomware disrupted Tribune Publishing and Data Resolution around the 2018 holiday period, encrypting networked resources, deleting shadow copies, and interfering with business operations such as newspaper printing and cloud-hosting services. The ex…

#Ryuk
2019-01-02 • Qihoo360

360's 2018 APT review highlights DPRK-linked activity through Lazarus Group and Group 123/APT37 sections rather than a single incident. The Lazarus section notes that vendor naming was becoming less clear, with FireEye separating financially motivated act…