« 2021 »

211 reports

2021-01-26 • JPCERT

JPCERT/CC’s English Operation Dream Job report analyzes Torisma and LCPDot malware used by Lazarus/Hidden Cobra. Torisma is a rundll32-executed downloader that loads C2 configuration from a signed local file, uses the VEST-32 algorithm and a repeated encr…

#DreamJob #Lazarus
2021-01-26 • Cisco Talos

Cisco Talos reported that multiple Talos researchers received messages linked to the same security-researcher targeting campaign described by Google TAG. One researcher was contacted on January 11 with the same lure seen in public reporting, and the attac…

#DreamJob
2021-01-25 • Google

The actors behind this campaign, which we attribute to a government-backed entity based in North Korea, have employed a number of means to target researchers which we will outline below. To date, we have only seen these actors targeting Windows systems as…

#DreamJob
2021-01-20 • JPCERT

JPCERT documented commonly available tools observed in Lazarus intrusions, emphasizing that the group supplements malware with legitimate utilities after gaining access. For lateral movement and network discovery, the excerpt names AdFind for Active Direc…

#Lazarus
2021-01-07 • NTTSecurity

NTT Security’s VB2020 presentation analyzed CryptoMimic, also known as Dangerous Password, an APT actor observed since around March 2018 targeting companies worldwide with emphasis on cryptocurrency organizations. The source describes initial LNK and macr…

#Youtube #CryptoMimic