« 2022 »

296 reports

2022-12-30 • Inter Lab

Interlab analyzed RambleOn, a malicious Android APK delivered to a South Korean journalist through an APT-style phishing approach. The attacker first contacted the journalist over WeChat about a sensitive topic, then pushed installation of a fake secure-m…

#Kimsuky #RambleOn #Mobile
2022-12-28 • KRNARS

The National Assembly Research Service assesses North Korean cyber operations as an international security issue that has evolved from early DDoS activity into ransomware, financial-institution attacks, and cryptocurrency theft. The report says North Kore…

#Trend
2022-12-27 • Kaspersky

Kaspersky reported that BlueNoroff, a financially motivated North Korea-linked actor, adopted new delivery methods to bypass Windows Mark-of-the-Web warnings. The campaign used ISO and VHD files, Visual Basic Script, Windows Batch files, executables, and …

#Bluenoroff #T1059.003 #T1041 #T1071.001 #T1204.001 #T1204.002 #T1566.002 #T1059.005 #T1566.001 #T1497.001 #T1027.002 #T1218.011 #T1055.002 #T1221 #T1218.007 #T1547.008 #T1553.005
2022-12-22 • Attack IQ

Andariel is presented as a North Korean RGB-linked Lazarus subgroup with a history of espionage against South Korean government and military targets and later financially motivated ransomware activity. The emulated 2021 South Korea campaign chains a malic…

#Andariel #T1082 #T1041 #T1071.001 #T1083 #T1057 #T1547.001 #T1053.005 #T1036.005 #T1105 #T1486 #T1049 #T1016 #T1074.001 #T1218.011 #T1218.010 #T1217 #T1033 #T1012 #T1120 #T1016.001 #T1197
2022-12-16 • SEKOIA

SEKOIA observed all known DPRK-linked intrusion sets active in 2022, with Lazarus and Kimsuky receiving the most reporting and showing continued cyberespionage and revenue-focused operations. Lazarus, Bluenoroff, and Andariel were described as overlapping…

#Trend