« 2022 »

296 reports

2022-08-03 • Ahnlab

AhnLab reports that Gwisin ransomware was increasingly targeting Korean companies with company-specific deployments rather than broad opportunistic infection. The malware is delivered as an MSI containing a DLL that requires a special execution argument, …

#Ransomware #Gwisin
2022-08-02 • Rekt

Rekt reported that the Nomad Bridge lost about $190 million after a June upgrade left the Replica contract initialized with a trusted 0x00 root. The flaw let attackers call process() without proving message validity, and copycats could repeat the transact…

#Cryptocurrency #Nomad
2022-07-31 • Xorhex

Xorhex uses an x86 FALLCHILL sample to demonstrate a YARA technique for resolving a near relative 0xE8 call target during malware hunting. The article explains that the called function address is calculated by adding the signed displacement in the call in…

#FALLCHILL
2022-07-28 • Kaspersky

We found links to previously observed cybercrime activities, new, formerly unknown samples used by the attackers during post-exploitation activities, a wealth of recent information about C2 infrastructure and the latest samples distributed to compromise v…

#Trend
2022-07-25 • KRCERT

KISA's first-half 2022 cyber threat trends report includes a DPRK-relevant expert column from ESTsecurity ESRC on recent changes and trends in Kimsuky's malicious payloads. The excerpt identifies the report as a broad cyber threat trends publication, so t…

#Kimsuky