« 2019 »

183 reports

2019-07-22 • Norfolk

The Lazarus Injector analysis covers a DPRK SWIFT-heist-related tool used to load a supplied payload into explorer.exe. The injector validates command-line parameters and payload file access, enumerates processes to locate Explorer, allocates remote memor…

#Lazarus
2019-07-18 • KRCERT

SupplyChain is described as a cyber threat report requiring defender review of the published evidence. The source discusses attacker tradecraft, victim targeting, malware or infrastructure references, and operational context that may affect detection engi…

#SupplyChain
2019-07-03 • Ahnlab

AhnLab analyzed a long-running wave of malicious HWP files that abused the Ghostscript CVE-2017-8291 “GhostButt” vulnerability embedded in EPS content. The report explains that HWP attacks against Korean users have often been targeted, with decoys crafted…

#CVE-2017-8291