« 2019 »

183 reports

2019-04-10 • Norfolk

Norfolk Infosec reviewed open-source evidence supporting BAE Systems’ SAS2019 reporting on DPRK-attributed SWIFT heist activity, including a PowerShell backdoor dubbed PowerBrace and possible overlap with TA505 intrusions. The source ties DPRK-linked fina…

#TA505
2019-04-09 • Peck Shield

PeckShield assessed that CoinBene was hacked despite the exchange's denial, citing asset movements that matched exchange theft patterns. Its DATAR tracking found many token types and high value assets leaving CoinBene wallets for competing exchanges in a …

#CoinBene
2019-03-26 • Fireeye

Mandiant/FireEye described multiple campaigns abusing a recently disclosed WinRAR ACE handling vulnerability. Observed payloads provided keylogging, password theft and RAT capabilities, with different malware families and varied targeting. Exploits typica…

#WinRAR
2019-03-20 • spuz

The source analyzes APT38’s DYEPACK framework and describes North Korean financially motivated operations against banks, including TP Bank, Bangladesh Bank, and Far Eastern International Bank. It says APT38 performs reconnaissance, spear phishing, and exp…

#APT38 #SWIFT #DYEPACK