« 2021 »

211 reports

2021-06-18 • Fluidattacks

Fluid Attacks links Lazarus to North Korea’s Reconnaissance General Bureau and describes the group as a state-sponsored operation active since at least 2009. The article says recent North Korean campaigns targeted South Korean government officials, financ…

#Lazarus
2021-06-15 • Secure Works

A campaign in 2022, named TraderTraitor, involved a set of malicious cryptocurrency trading applications that targeted employees of organizations engaged in blockchain research. NICKEL GLADSTONE has also increasingly targeted cryptocurrency exchanges and …

#NickelGladstone #CTG-6459
2021-06-15 • Kaspersky

Kaspersky attributed a 2021 South Korea-focused campaign to Andariel, a Lazarus sub-group, based on code overlap with earlier Andariel malware and distinctive post-exploitation command usage. The activity used weaponized Korean Word documents and PDF-like…

#Andariel #Ransomware #Manuscrypt #T1041 #T1113 #T1071.001 #T1059.007 #T1204.002 #T1057 #T1583.003 #T1566.001 #T1036.005 #T1497.001 #T1486 #T1573.001 #T1049 #T1095 #T1027.003 #T1584.006
2021-06-03 • Sands Lab

This Korean malware analysis covers a malicious document named as an International Constitution Day forum file that likely used phishing to reach a broad target set. Enabling content runs obfuscated macros that contact rukagu.mypressonline.com, fetch /le/…

#Thallium
2021-06-01 • Malwarebytes

Malwarebytes tracked Kimsuky, also known as Thallium, Black Banshee, and Velvet Chollima, using phishing sites, malicious documents, and scripts against high-profile South Korean government targets. One lure translated as “Ministry of Foreign Affairs Edit…

#Kimsuky #AppleSeed #T1082 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1113 #T1560 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.007 #T1027 #T1566.001 #T1547.001 #T1585.002 #T1059.001 #T1585.001 #T1001 #T1598 #T1583 #T1218.010 #T1134 #T1025
2021-05-24 • Ahnlab

AhnLab describes malicious Excel and Word documents disguised as normal Korean business or event files, including card-company themed spreadsheets and forum-related documents that prompt users to enable macros. Once macros run, the samples fetch additiona…

#Phishing