« 2022 »

296 reports

2022-06-30 • Prelude

Prelude describes an APT38 spear-phishing chain against pharmaceutical companies in 2020 that used ISO containers to bypass Mark-of-the-Web propagation. The tradecraft packages a decoy job-offer PDF with an application inside an ISO built using PackMyPayl…

#APT38 #Pharmaceuticals
2022-06-24 • Certi K

CertiK analyzes the June 23, 2022 Harmony Horizon Bridge exploit, estimating losses of about $97 million from multiple attack transactions across the bridge between Harmony and Ethereum. The attacker obtained control sufficient to make the MultiSigWallet …

#Cryptocurrency #Harmony
2022-06-24 • Rekt

The Harmony Bridge incident drained about $100 million after two addresses in a 2-of-5 multisig were compromised, allowing the attacker to move assets from the ETH, ERC20, BUSD and BSC bridge components. The source lists the compromised signer addresses, …

#Cryptocurrency #Harmony
2022-06-20 • Secu I

SECUINSIDE analyzed malicious HWP documents that abused embedded OLE objects rather than patched HWP vulnerabilities to trigger execution through user clicks. The campaign used spear-phishing emails aimed at people connected to North Korea-related topics,…

2022-06-15 • Prelude

Prelude’s TTP Tuesday entry builds a defensive emulation chain for APT38 TraderTraitor tradecraft described by CISA, focusing on fake cryptocurrency trading or price-prediction applications used for initial access. The simulated CryptoSpy application is a…

#APT38 #CryptoSpy