« 2022 »

296 reports

2022-05-18 • Prelude

Prelude released an APT38-themed emulation chain based on Castov malware used by DarkSeoul against South Korean financial industry and government targets. The excerpt says Castov acted as a downloader for second-stage malware, including payloads hidden in…

#APT38 #Castov
2022-05-12 • Elliptic

In the recent Ronin Bridge hack attributed to North Korea’s Lazarus Group, the hackers made extensive use of Tornado Cash to launder some of the stolen cryptoassets from the heist, which at the time of the theft totalled $540 million. Unlike simple P2P ex…

#Cryptocurrency #DeFi
2022-05-10 • Secure Works

Sophos profiles NICKEL KIMBALL as a North Korea-linked espionage group active since at least 2012 and aligned with aliases including Kimsuky, APT43, Emerald Sleet, THALLIUM, TA406, TA427, SharpTongue, and Velvet Chollima. The group targets NGOs, think tan…

#NickelKimball