« 2019 »

183 reports

2019-11-04 • Qianxin

QiAnXin’s threat intelligence team found Lazarus-linked attack samples for both Windows and macOS, including a Windows lure built around a psychological test that prompted users to enable macros. The Windows sample released and executed a PowerShell backd…

#Lazarus
2019-11-03 • Issuemakers Lab

IssueMakersLab reported that a North Korean hacker group, labeled group B in the post, was linked to the Kudankulam Nuclear Power Plant compromise in India. The post says the shared image showed malware history and identified a 16-character password, dkwe…

#KKNPP
2019-10-31 • USCISA

CISA’s MAR-10135536-8 analyzes `HOPLIGHT`, a set of Trojan malware variants used by the North Korean government and tracked by the U.S. Government as `HIDDEN COBRA`. The report covers twenty malicious executables, including sixteen proxy applications that…

#Hoplight
2019-10-23 • Fortinet

FortiGuard Labs analyzed NukeSped RAT samples linked to North Korea’s HIDDEN COBRA activity and compared them with known FALLCHILL tooling. The samples used encrypted strings, dynamic API resolution, persistence through Run keys or services, and a remote-…

#NukeSped #HiddenCobra
2019-10-20 • kino

The source analyzes a Kimsuky-style malicious HWP document disguised as a KINU expert consultation request on Korea-related policy issues. Embedded exploit and shellcode content decrypted a payload, injected code into HimTrayIcon.exe and userinit.exe, and…

#Kimsuky