« 2022 »

296 reports

2022-06-02 • Prelude

WannaCry is described as an APT38-themed chain that spread in May 2017 by using EternalBlue and DoublePulsar against unpatched Windows systems. The excerpt highlights WannaCry’s kill-switch domain check, where successful resolution caused the ransomware t…

#APT38 #WannaCry
2022-06-02 • CN-SEC

Anheng CERT attributed a renewed Dream Job-style operation to Lazarus after observing Binance developer recruitment lures aimed at job seekers, with the suspected objective of cryptocurrency theft. The delivery chain used password-protected PDF decoys alo…

#DreamJob
2022-06-01 • Somansa

Somansa reported continued North Korea-attributed abuse of HWP OLE objects against South Korean users even after Microsoft patched CVE-2022-30190. The analyzed lures included broadcast invitation requests, surveys for North Korean defector advisers, inter…

#OLE
2022-05-31 • Thales Group

Thales' 2022 Cyber Threat Handbook profiles North Korea's cyber apparatus as a Bureau 121-centered ecosystem rather than a single monolithic Lazarus actor. The DPRK section links Lazarus to espionage and destabilization operations, cites the Sony Pictures…

#Trend #ATK117 #ATK3 #ATK4
2022-05-25 • Prelude

Prelude's TTP Tuesday article uses the 2014 Sony Pictures compromise to model APT38/Guardians of Peace tradecraft. It summarizes the operation's political trigger around The Interview, the leaking of Sony emails, employee records and unreleased films, des…

#APT38 #Blockbuster