« 2020 »

197 reports

2020-05-17 • hackingump

PebbleDash is described as a North Korea-linked Hidden Cobra/APT38/Lazarus remote access tool whose FakeTLS mechanism hides command-and-control traffic inside traffic that resembles a normal TLS handshake. The analyzed sample used dynamic library loading …

#PebbleDash
2020-05-15 • Malwarelab

MalwareLab analyzed a Lazarus-attributed validator from malicious Word documents impersonating Lockheed Martin and linked the samples to a broader campaign probably aimed at military contractors doing business with South Korea. The documents embedded two …

#YARA #Lazarus
2020-05-12 • USCISA

CISA, the FBI, and the Department of Defense reported three malware variants used by the North Korean government, which the U.S. Government tracks as HIDDEN COBRA activity. U.S. Cyber Command released samples for the variants to VirusTotal so defenders co…

2020-05-05 • Objective-see

Objective-See analyzed a macOS variant of the Lazarus-linked Dacls RAT distributed as a TinkaOTP Apple disk image and application bundle. The initial remote infection path was unknown, but the packaging resembled earlier Lazarus activity that used trojani…

#Dacls #macOS