« 2022 »

296 reports

2022-04-26 • Zscaler

Zscaler ThreatLabz linked a South Korea-focused phishing and malware campaign to Lazarus with high confidence after correlating reused infrastructure, attacker-controlled Dropbox accounts, registrant email addresses, sender infrastructure, and domains tie…

#Phishing #Lazarus
2022-04-21 • Stairwell

Stairwell analyzed a GOLDBACKDOOR deployment chain from malicious artifacts NK News received in a spear-phishing campaign targeting journalists focused on the DPRK. The campaign delivered a ZIP containing a large Windows shortcut named “Kang Min-chol Edit…

#YARA #APT37 #GoldBackdoor
2022-04-19 • Rekt

REKT’s Big Phish article connects the Ronin bridge theft to FBI attribution that named the North Korean Lazarus Group and discusses CISA reporting on DPRK state-sponsored targeting of cryptocurrency organizations. The source emphasizes Lazarus and BlueNor…

#Cryptocurrency #Bluenoroff #NexusMutual #DeFiance
2022-04-15 • Dragos

Dragos' 2021 ICS/OT Cybersecurity Year in Review covers industrial threat activity, ransomware pressure on infrastructure, incident response lessons, and recurring security weaknesses in operational technology environments. The report tracks known activit…

#Trend #WASSONITE #T1082 #T1140 #T1041 #T1113 #T1555 #T1560 #T1083 #T1036 #T1071 #T1053 #T1566 #T1059 #T1480 #T1055 #T1078 #T1127 #T1189 #T1049 #T1574 #T1589 #T1016 #T1591 #T1547 #T1614 #T1217 #T1573 #T1074 #T1056 #T1033 #T1132 #T1021 #T1564 #T1584 #T1505 #T0807 #T0840 #T0884 #T0888 #T1602 #T0822 #T0858 #T0859 #T0806 #T0817 #T0819
2022-04-14 • Symantec

Symantec observed the North Korea-linked Lazarus group targeting South Korean chemical-sector organizations in activity assessed as a continuation of Operation Dream Job, tracked by Symantec as Pompilus. The campaign used fake job-offer lures that led to …

#DreamJob #MagicLine4NX #Pompilus