« 2020 »

197 reports

2020-02-14 • USCISA

CISA, FBI, and DoD analyzed ARTFULPIE as a North Korean government-linked Trojan variant associated with HIDDEN COBRA activity. The implant functions as a downloader and in-memory loader, retrieving a DLL from a hardcoded URL and manually loading it into …

#ARTFULPIE
2020-02-14 • USCISA

CISA, FBI, and DoD analyzed HOPLIGHT, a North Korean government-linked malware set associated with HIDDEN COBRA. The report covers twenty malicious executables, including proxy applications that mask traffic between infected hosts and remote operators. Se…

#Hoplight
2020-02-06 • Bushidotoken

The source provides a narrative history of Lazarus Group operations, including the Bangladesh Bank SWIFT theft attempt and WannaCry ransomware activity. It describes the Bangladesh Bank case as a phishing-enabled intrusion that reached systems used for SW…

#Lazarus
2020-01-08 • Kaspersky

Kaspersky reported continued Lazarus Group operations against cryptocurrency businesses after Operation AppleJeus. The actor used fake companies and manipulated applications to gain trust, then delivered macOS and Windows malware through multi-stage infec…

#Cryptocurrency #AppleJeus