« 2023 »

627 reports

2023-08-21 • Hauri

Hauri reported a Kimsuky malware family called ReconShark that used Zoom meeting-information lures against organizations and individuals handling North Korea-related information. The malware displayed a decoy Zoom document from attacker infrastructure, co…

#Kimsuky #ReconShark
2023-08-19 • Birmingham Cyber

Riding with the Chollimas describes a 2023 investigation into QRLOG, a simple homemade RAT bundled inside a fake QR generator and later attributed by CrowdStrike with high confidence to Labyrinth Chollima. The malware hid base64-encoded code in a variable…

#LabyrinthChollima #QRLog
2023-08-09 • Ahnlab

ASEC describes weekly changes in CHM malware impersonating Korean financial and insurance institutions, where execution begins through hh.exe, decompiled internal HTML, and a generated JSE script launched by wscript. One variant preserved registry-based p…

#CHM