« 2022 »

296 reports

2022-08-26 • Secu I

Appleseed v2.1 was delivered through a JavaScript loader disguised with a decoy document, double Base64-encoded payloads, and string-splitting obfuscation to evade detection. The loader drops an encoded Appleseed DLL under ProgramData, decodes it with cer…

#AppleSeed
2022-08-24 • SKShildus

SK Shieldus analyzes the Gwisin ransomware group as a Korea-focused operation that has targeted domestic medical, pharmaceutical, financial, and other enterprises since 2021, with no confirmed foreign victims at the time of reporting. The report maps the …

#Ransomware #Gwisin #T1059.003 #T1140 #T1587.001 #T1041 #T1608.001 #T1083 #T1589.001 #T1490 #T1486 #T1590 #T1003.001 #T1021.001 #T1047 #T1036.003 #T1021.002 #T1021.006 #T1110 #T1021.004 #T1595.002 #T1070.001 #T1218.007 #T0807
2022-08-18 • Mandiant

Mandiant describes a method for clustering malicious Office Open XML documents by ZIP local-file-header metadata such as CRC-32 values, uncompressed sizes, and embedded file names. The DPRK-relevant example uses a YARA rule to detect OOXML documents carry…

#UNC1130