« 2020 »

197 reports

2020-09-08 • NTU

This academic article assesses North Korea's cyber strategy as a low-cost asymmetric capability used alongside nuclear and missile programs to gather intelligence, coerce rivals, and generate revenue. It describes DPRK operators and state-sponsored groups…

2020-08-27 • USJustice

The Panel of Experts concluded that North Korea’s “cyberattacks on [South Korean] targets have been increasing in number, sophistication and scope since 2008, including a clear shift in 2016 to attacks focused on generating financial revenue. In or about …

#AlgoCapital #CoinTiger
2020-08-26 • USCISA

CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea’s BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The advisory says the group has targeted financial ins…

#BeagleBoyz #FASTCash2 #T1082 #T1119 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1020 #T1560 #T1115 #T1083 #T1036 #T1027 #T1071 #T1548.003 #T1204 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1199 #T1105 #T1219 #T1055 #T1553.002 #T1552.004 #T1562.001 #T1486 #T1129 #T1489 #T1078 #T1133 #T1053.003 #T1190 #T1203 #T1189 #T1049 #T1098 #T1087 #T1016 #T1070.006 #T1021.001 #T1574.001 #T1217 #T1106 #T1573 #T1095 #T1056 #T1010 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1110 #T1561.002 #T1202 #T1070.003 #T1565.001 #T1021 #T1505.003 #T1027.005 #T1056.004 #T1218.001 #T1562.003 #T1014 #T1053.004 #T1101 #T1565.002 #T1565.003 #T1562.006
2020-08-20 • KRCERT

The source analyzes phishing email attack cases from initial email delivery through credential theft and attacker mail-sending infrastructure. It describes document-themed lures using PDF, PowerPoint, Word, and HWP files, password-processing behavior in w…

#Phishing
2020-08-19 • USCISA

This campaign utilized compromised infrastructure from multiple countries to host its command and control (C2) infrastructure and distribute implants to a victim's system. Government partners, DHS and FBI identified Remote Access Trojan (RAT) malware vari…

#BLINDINGCAN
2020-08-18 • With Secure

F-Secure investigated a Lazarus Group intrusion against an organization in the cryptocurrency sector and tied it to a broader phishing campaign active since at least January 2018. Initial access came through a LinkedIn-delivered job advert lure that used …

#Cryptocurrency #Whitepaper #YARA #Lazarus #T1059.003 #T1070.004 #T1071.001 #T1112 #T1083 #T1566.003 #T1059.005 #T1053.005 #T1059.001 #T1552.001 #T1027.002 #T1003.001 #T1218.005 #T1021.001 #T1055.002 #T1543.003 #T1547.005 #T1070.001 #T1021.005 #T1078.002
2020-08-14 • USCISA

CISA observed phishing emails carrying Microsoft Word documents with malicious VBA macros that deploy KONNI, a RAT capable of file theft, keylogging, screenshots, and arbitrary code execution. The macro tries to trick users into enabling content by changi…

#Phishing #Konni #T1082 #T1059.003 #T1140 #T1070.004 #T1113 #T1071.001 #T1112 #T1115 #T1083 #T1056.001 #T1555.003 #T1057 #T1566.001 #T1547.001 #T1059.001 #T1036.005 #T1132.001 #T1105 #T1546.015 #T1016 #T1548.002 #T1218.011 #T1048.003 #T1134.002 #T1033 #T1547.009