« 2020 »

197 reports

2020-11-23 • Rapid7

Some organizations track North Korean clusters or groups, such as Bluenoroff, APT37, and APT38 separately, while other organizations track some activity associated with those groups as Lazarus Group. Malware used by Lazarus Group has correlated to other r…

#Unit121 #Bureau121 #Lazarus
2020-11-16 • ESET

ESET described a Lazarus supply-chain attack in South Korea that abused WIZVERA VeraPort, software commonly used by government and banking websites to install required security components. The attackers compromised websites that already supported VeraPort…

#BookCodes #SupplyChain #MagicLine4NX #VeraPort #Lazarus #T1584.004 #T1587.001 #T1041 #T1071.001 #T1195.002 #T1036 #T1055 #T1553.002 #T1027.002 #T1573.001 #T1588.003 #T1106 #T1547.005
2020-11-16 • Reversing Labs

ReversingLabs analyzed a PoorWeb campaign built around malicious Hangul Word Processor documents aimed at a victim organization and related Korean-language HWP attacks seen from March 2019 through September 2020. The initial documents abused HWP compound-…

#T1106
2020-11-05 • Mcafee

McAfee ATR expanded its Operation North Star analysis by examining the campaign's command-and-control backend, showing how the operators selected and assessed victims before deciding whether to continue exploitation. The campaign used LinkedIn conversatio…

#NorthStar