« 2021 »

211 reports

2021-12-30 • kino

A Korean malware-analysis post tracks ongoing Kimsuky/Thallium activity using the GoldDragon/BravePrince cluster, noting a newer sample that keeps the usual daum-mail information-theft behavior while adding encoded DLL and API-name resolution. The author …

#Kimsuky #GoldDragon #BravePrince
2021-12-24 • Ahnlab

AhnLab reports malicious Hangul Word Processor documents themed around North Korea-related construction activity that rely on embedded objects and a user-clicked hyperlink rather than an exploit. When the lure is opened and clicked, a legitimate OneDrive …

#Kimsuky
2021-12-22 • Threatray

ThreatRay links malware samples from Malwarebytes, Kaspersky, and KrCERT reporting on South Korea-focused activity to shared TigerDownloader and TigerRAT families. The earlier reports attributed the activity to Lazarus or more specifically Andariel, a Laz…

#Andariel #TigerRAT #T1041 #T1113 #T1071.001 #T1056.001 #T1059.007 #T1204.002 #T1057 #T1583.003 #T1566.001 #T1036.005 #T1497.001 #T1486 #T1573.001 #T1189 #T1049 #T1095 #T1027.003 #T1584.006
2021-12-06 • INSS

The INSS paper assesses that North Korea's cyber capabilities strengthened under Kim Jong Un and became an important asymmetric instrument for the regime. It argues that Pyongyang uses cyber operations for economic and political gains, including sanctions…

2021-12-02 • SOCRadar

SOCRadar profiles Lazarus Group as a DPRK Reconnaissance General Bureau-linked threat actor also tracked under names such as Hidden Cobra, Zinc, Guardians of Peace, and Stardust Chollima. The source emphasizes that Lazarus blends political, espionage, dis…

#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
2021-11-29 • Kaspersky

Kaspersky describes ScarCruft/APT37/Temp.Reaper activity against North Korean defectors, journalists covering North Korea, and Korean Peninsula-related organizations after assisting a compromised news organization. The investigation found a victim infecte…

#Scarcruft #Chinotto #T1082 #T1140 #T1041 #T1113 #T1071.001 #T1059.005 #T1566.001 #T1547.001 #T1059.001 #T1036.005 #T1573.001 #T1033 #T1560.002 #T1584.006
2021-12-02
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865