« 2019 »

183 reports

2019-12-03 • Objective-see

Objective-See analyzed a Lazarus-linked macOS implant delivered through a trojanized UnionCryptoTrader application, continuing the group’s pattern of targeting cryptocurrency exchange users and administrators with fake trading software. The infection chai…

#AppleJeus #Fileless #Lazarus
2019-12-02 • Threat Book

The FreeBuf article profiles Lazarus as a North Korea-linked group also known as APT38 or Guardians of Peace, summarizing activity from early political attacks against the United States and South Korea through later financial, ransomware, cryptocurrency, …

#Lazarus
2019-11-22 • Ahnlab

AhnLab ASEC observed malicious HWP documents that create script files in the Windows Startup folder so payload activity runs after reboot rather than immediately on document execution. One lure used a Korean National Intelligence Studies Association chair…

#Phishing
2019-11-12 • lysine7

The analysis examines two suspicious HWP samples found on VirusTotal that used different filenames but shared the same embedded PostScript component. One lure posed as a new coin listing application and created an executable in the Windows Startup folder …

#SlackBot
2019-11-12 • Strangereal Intel

Strangereal Intel reviewed October 2019 Lazarus activity involving multiple document-based intrusions. One HWP lure targeted South Korean CES 2020 exhibitors through CVE-2017-8291/EPS execution, collected host, disk, process, and file information, and con…

#Lazarus #T1082 #T1005 #T1112 #T1115 #T1124 #T1057 #T1059 #T1055 #T1049 #T1087 #T1016 #T1010 #T1012 #T1132 #T1060 #T1064 #T1085 #T1086 #T1022 #T1179 #T1089