« 2022 »

296 reports

2022-07-20 • Securonix

Securonix tracked STIFF#BIZON as an ongoing campaign against high-value targets including the Czech Republic and Poland, with some observed artifacts and tradecraft associated with Konni activity linked in the report to North Korea’s APT37. The intrusion …

#Konni #StiffBizon #T1082 #T1119 #T1059.003 #T1070.004 #T1041 #T1113 #T1020 #T1071.001 #T1204.002 #T1555.003 #T1057 #T1059.005 #T1566.001 #T1053.005 #T1539 #T1059.001 #T1053 #T1132.001 #T1105 #T1548.002 #T1134.001 #T1033 #T1569.002 #T1543.003 #T1560.003 #T1007 #T1027.005 #T1606.001
2022-07-14 • Harmony One

Harmony's rolling incident update documents the June 23, 2022 Horizon Bridge hack, in which approximately $100 million was stolen through 11 unauthorized transactions from the Ethereum side of the bridge. The incident response found no evidence of smart-c…

#Cryptocurrency #Harmony
2022-07-12 • Secrss

The translated JPCERT/CC analysis links YamaBot to Lazarus activity and describes the malware as a Go-based tool targeting both Windows and Linux environments. YamaBot communicates with C2 servers through HTTP requests, using a Base64-encoded User-Agent a…

#YamaBot
2022-07-08 • Hauri

Hauri analyzed a dropper disguised as an ipTIME router firmware update that displayed a fake upgrade window while executing malicious activity in the background. The malware decrypted embedded data, created a mutex named like a Windows update artifact, wr…

2022-07-06 • Stairwell

Stairwell's Maui ransomware report provides a reverse-engineering analysis of a lesser-known ransomware family first collected in April 2022. Maui appears manually operated: an attacker supplies a target path at execution time, and the malware encrypts se…

#Ransomware #Maui