« 2020 »

197 reports

2020-09-29 • JPCERT

JPCERT/CC analyzes BLINDINGCAN, a Lazarus/Hidden Cobra malware family loaded through a DLL after network intrusion. The malware stores encrypted configuration in the sample, a nearby file, or a registry value under HKLM\SOFTWARE\Microsoft\Windows\CurrentV…

#BLINDINGCAN #Lazarus
2020-09-19 • Secure Works

NICKEL ACADEMY is Sophos reporting on North Korean Reconnaissance General Bureau cyber operations that are not assigned to a narrower subgroup. The profile says the activity has operated since at least 2009, with South Korean government and commercial org…

#NickelAcademy #CTG-2460
2020-09-16 • Intezer

Intezer surveys the rise of Linux-targeting APT campaigns and identifies North Korea as one of the major nation-state origins, alongside China, Russia, and the United States, in documented Linux espionage tooling from the prior decade. The source does not…

2020-09-11 • Unibright

Unibright said a recovery key for one of its company HD wallets was exposed, enabling unauthorized access to token lock contracts tied to that wallet. The attacker called transfer functions on the lock contracts and moved 1.93 million locked UBT, along wi…

#Unibright
2020-09-08 • Issuemakers Lab

North Korea-linked RGB-D3 malware was distributed with a lure themed around a General Dynamics Mission Systems job description. The archived evidence is limited, but the theme points to defense-sector social engineering against users interested in a major…

#Defense #RGB-D3