« 2022 »

296 reports

2022-10-12 • Ahnlab

AhnLab explains how attackers use Windows Remote Desktop Protocol for initial access, lateral movement, and persistence after obtaining credentials or enabling remote desktop services. The report cites ransomware and APT cases where attackers used RDP dir…

#Trend #RDP
2022-10-09 • BBC

BBC’s “Lazarus Heist live” is a special episode of the Lazarus Heist series recorded with an audience in New York. The source excerpt supplies only the event-style episode description and surrounding series listings, not a technical case study or indicato…

#Podcast #Lazarus
2022-10-05 • ESET

ESET’s T2 2022 threat report flags Lazarus activity within a broader threat landscape review, including an Operation In(ter)ception campaign against macOS users. The DPRK-linked section says the malware was disguised as a Coinbase cryptocurrency-platform …

#Trend
2022-09-30 • ESET

ESET attributes 2021 attacks in the Netherlands and Belgium to Lazarus with high confidence, citing malware modules, a code-signing certificate, and overlap with Operation In(ter)ception and Operation DreamJob tradecraft. The campaign used Amazon-themed f…

#BYOVD #T1059.003 #T1140 #T1584.004 #T1587.001 #T1071.001 #T1204.002 #T1566.003 #T1566.001 #T1547.001 #T1132.001 #T1574.002 #T1027.002 #T1573.001 #T1218.011 #T1070.006 #T1106 #T1560.002 #T1014 #T1547.006
2022-09-30 • ESET

ESET documents FudModule, an 88,064-byte user-mode DLL used in a Lazarus attack on a corporate endpoint in the Netherlands in October 2021. The module was delivered alongside other Lazarus-attributed tools such as HTTP(S) backdoors, downloaders, and uploa…

#BYOVD
2022-09-30 • ESET

When compared to other APTs using BYOVD, this Lazarus case is unique as it possesses a complex bundle of ways to disable monitoring interfaces that was so far never seen in the wild. In our session we dive into a deep technical analysis of a malicious com…

#BYOVD #Youtube
2022-09-29 • Microsoft

Microsoft attributed a 2022 social-engineering campaign to ZINC, a North Korea-based group now tracked as Diamond Sleet, targeting employees in media, defense and aerospace, and IT services organizations in the US, UK, India, and Russia. The operators bui…

#Zinc
2022-09-29 • Belfercenter

The Belfer Center's 2022 National Cyber Power Index evaluates how thirty states demonstrate cyber capability and intent across national objectives. Its framework treats cyber power as broader than destructive operations, including espionage, resilience, s…

#NCPI