« 2022 »

296 reports

2022-11-23 • Joe Słowik

Pylos documents a domain-hunting pivot from suspicious mail-themed infrastructure into a broader set of domains assessed as possibly linked to an in-progress Kimsuky campaign. The activity centered on East Asian, especially South Korean, hosting and spoof…

#Kimsuky
2022-11-22 • Avertium

When social engineering is combined with highly targeted spear phishing, it can be difficult to spot. Tactics & Techniques ZINC (a sub-group of Lazarus) spent a lot of time during 2020 establishing a research blog and several Twitter profiles to interact …

#Zinc
2022-11-15 • Kaspersky

Kaspersky reported that Lazarus continued using the DTrack backdoor three years after its 2019 discovery, with telemetry showing activity in Europe, Latin America, the Middle East, Asia, and the United States. DTrack supports file upload, download, execut…

#DTrack
2022-11-14 • ESET

ESET’s T2 2022 APT Activity Report is a broad multi-actor survey that includes continued North Korea-aligned activity during the May–August 2022 reporting period. The report frames DPRK-linked operations alongside Russia-, China-, and Iran-aligned activit…

#Trend
2022-11-08 • Quill Audits

QuillAudits analyzed Deribit’s November 2022 hot-wallet compromise, in which attackers drained about $28 million from BTC, ETH, and USDC hot wallets. Deribit paused withdrawals, said client assets and cold-storage addresses were unaffected, and covered th…

#Deribit
2022-11-03 • Rekt

REKT covered Deribit’s $28 million hot-wallet theft from Ethereum and Bitcoin networks, including 6,968 ETH, 3.4 million USDC, and 691 BTC. Deribit said the loss would be covered by reserves, that most user funds were in cold storage, and that withdrawals…

#Cryptocurrency #Deribit