« 2021 »

211 reports

2021-05-23 • BBC

BBC’s S1.6 Cyber slaves episode page describes North Korean hackers living a double life overseas and references a “hacker hotel.” The excerpt provides operational context rather than malware or IOC detail, highlighting how overseas personnel and controll…

#Podcast #Lazarus
2021-05-21 • Macnica

Macnica Networks and TeamT5’s 2020 Japan APT landscape report is a broad espionage study of attacks against Japanese organizations, but its DPRK-relevant material includes a dedicated “CloudDragon (Kimsuky)” section under new TTPs and RATs. The excerpt fr…

#Trend #CloudDragon #T1140 #T1071.001 #T1027 #T1204.002 #T1071 #T1518.001 #T1566.001 #T1547.001 #T1053.005 #T1059.001 #T1036.005 #T1574.002 #T1133 #T1055.012 #T1218.011 #T1021.001 #T1574.001 #T1047 #T1560.001 #T1543.003 #T1087.002 #T1482 #T1070.001 #T1003.002 #T1053.002 #T1003.003
2021-05-21 • Threat Book

ThreatBook reports a Konni APT campaign using North Korea-related geopolitical lures against Russian-facing organizations. The spear-phishing documents used Russian-language themes such as sanctions’ impact on the DPRK situation and proposals for resolvin…

#Konni #T1082 #T1059.003 #T1140 #T1041 #T1071.001 #T1059.007 #T1204.002 #T1566.001 #T1573.001 #T1132.002 #T1055.001 #T1033 #T1569.002 #T1543.003 #T1202 #T1027.001
2021-05-06 • 0xthreatintel

The source links Unit180/Lazarus targeting of Japan to the VSingle and ValeforBeta malware families and compares them with Torisma and LCPDot from Operation Dream Job. The analysis says both malware samples share exported functions and DllEntryPoint logic…

#Lazarus