« 2021 »

211 reports

2021-09-01 • Igloo

IGLOO’s first-half 2021 Kimsuky trend report documents repeated Korea-focused phishing and malware operations that used malicious documents, VBA or PowerShell logic, HWP-delivered DLL/VBS stages, and attacker-controlled web infrastructure to collect host …

#Kimsuky
2021-08-23 • Inquest

A JavaScript file masquerading as a PDF used a Korean Foreign Ministry newsletter lure to display a benign document while decoding and launching hidden payloads. The infection chain embedded Base64 data, extracted a legitimate lure file and a UPX-packed x…

#Kimsuky