« 2021 »

211 reports

2021-03-31 • Google

Google TAG says the North Korean government-backed actors targeting security researchers expanded their operation by creating a fake offensive-security company called SecuriElite on March 17. The site and associated LinkedIn and Twitter personas posed as …

#DreamJob
2021-03-29 • Ahnlab

AhnLab's Operation Dream Job report summarizes malicious activity against people interested in aerospace and defense-industry employment. The campaign used social-media recruiter personas and job-opportunity lures to deliver malware to targets in sensitiv…

#DreamJob
2021-03-23 • Carnegie Endowment

Carnegie's financial-sector incident timeline includes a DPRK-relevant entry stating that Lazarus used trojanized decentralized-finance applications in an April 2022 spearphishing campaign. The timeline labels the activity as a high-confidence state-spons…

#Trend #Cryptocurrency #BangSwift #Finance #Qubit #Liquid #DragonEx #NiceHash #RedBanc #CosmosBank #Zaif #FEIB #Bancomext #Bithumb1 #Bithumb2 #Coinis #CostaRicanFI #GuatemalanFI #NigerianBank #StandardBank #TunisianFI #UnionBank #Youbit #TPBank #LiberianFI #KuwaitBank #Rakyat #Yapizon #Coincheck #Bithumb3 #Bithumb4 #Coinrail #bZx
2021-03-23 • Sygnia

Sygnia links a double-extortion ransomware intrusion to a new, undocumented variant of the Lazarus-associated MATA malware framework that was used to deploy TFlower ransomware. The report says the relationship between Lazarus and TFlower requires further …

#MATA #TFlower #Lazarus #T1070.004 #T1113 #T1112 #T1053.005 #T1036.005 #T1552.001 #T1486 #T1008 #T1573.001 #T1021.001 #T1562 #T1055.001 #T1021.002 #T1070.003 #T1021.004 #T1547.005 #T1572 #T1070.001
2021-02-28 • PWC

PwC’s 2020 retrospective notes North Korea-based Black Banshee, also known as Kimsuky, registering domains that impersonated healthcare and pharmaceutical organizations involved in COVID-19 vaccine and treatment research. The observed targeting covered en…

#AppleSeed #BlackBanshee #BlackArtemis #VeraPort #ShowState #BlackShoggoth #T1082 #T1140 #T1005 #T1070.004 #T1041 #T1083 #T1056.001 #T1036 #T1027 #T1071 #T1204 #T1057 #T1547.001 #T1566 #T1059 #T1195 #T1490 #T1486 #T1489 #T1133 #T1068 #T1221 #T1187
2021-02-25 • Kaspersky

Kaspersky reports that Lazarus used the ThreatNeedle malware cluster, an advanced Manuscrypt/NukeSped variant, in attacks against defense-industry organizations in more than a dozen countries. The campaign began with carefully tailored COVID-19-themed spe…

#ThreatNeedle #Defense #Lazarus #T1082 #T1059.003 #T1140 #T1070.004 #T1041 #T1071.001 #T1112 #T1083 #T1204.002 #T1566.002 #T1057 #T1547.001 #T1135 #T1070.002 #T1049 #T1132.002 #T1016 #T1036.004 #T1090.001 #T1036.003 #T1560.001 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1104 #T1557.001 #T1070.003 #T1007 #T1572