« 2021 »

211 reports

2021-10-14
MGNR
#MGNR
2021-10-21 • NSFOCUS

NSFOCUS profiles Kimsuky, also known as Thallium, CloudDragon, Velvet Chollima, and BabyShark, as a North Korea-linked APT active since at least 2012–2013 and primarily focused on South Korean government, military, think-tank, academic, media, human-right…

#Kimsuky
2021-10-14 • MGNR

MGNR disclosed that an October 2021 targeted attack likely began with a phishing email impersonating a recognized contact and carrying a fake DOCX tied to a Pantera-themed term sheet. The intrusion probably installed a keylogger and stole password manager…

#MGNR
2021-10-11 • Telsy

Telsy analyzed Lazarus Group samples tied to the AppleJeus operation, again using a trojanized cryptocurrency trading application as the initial lure. The campaign packaged a malicious version of QtBitcoinTrader in an MSI installer that dropped files unde…

#AppleJeus #Lazarus
2021-10-07 • KRCERT

In general, it targets bulletin boards on vulnerable websites, uploads web shells, and takes control by exploiting the host server's local privilege escalation. During the analysis, we further examined the commands (packets) and command structures used by…

#BookCodes