« 2023 »

627 reports

2023-06-23 • Phylum

Phylum observed a coordinated npm supply-chain campaign in which malicious packages were published in pairs that had to run sequentially on the same host. The first package used a preinstall hook to install sync-request, contact an attacker server, and wr…

#NPM
2023-06-23 • Ahnlab

Considering that the words used in the malware and the executed script code are similar to that of previously analyzed codes, it is suspected that the same threat group (Kimsuky) is also the creator of this malware. Both the script present in the above UR…

#Kimsuky
2023-06-23 • Recorded Future

Kimsuky is the most common threat group, followed by Lazarus Group and APT37. South Korea and the United States are the most common targets, but North Korean threat actors have a global reach, targeting entities in at least 29 countries. Despite its centr…

#Trend #Whitepaper
2023-06-22 • WSJ

North Korean hackers are described as financially motivated operators who moved from high-profile disruption, including Sony and WannaCry, into large-scale theft from banks and cryptocurrency businesses. The WSJ transcript cites Chainalysis estimates that…

#Podcast
2023-06-21 • Trmlabs

TRM Labs frames North Korean cryptocurrency theft as a growing revenue stream that has expanded as sanctions, border closures, and weakened traditional income channels increased pressure on the regime. The excerpt highlights attacks on cryptocurrency busi…

#Trend #Cryptocurrency
2023-06-21 • Elastic

Elastic analyzed a REF9134 intrusion at a prominent Japanese cryptocurrency exchange where an adversary used JOKERSPY components on macOS systems. The activity involved the self-signed Swift binary xcc, which checked permissions such as Full Disk Access, …

#JokerSpy #REF9134
2023-06-20 • Atomicwallet

The team has researched various potential causes, the most probable of which are virus targeting on local users devices, infrastructure breach, malware code injection, or a man-in-the-middle attack. We've engaged with the leading Crypto Investigators - Ch…

#Cryptocurrency #AtomicWallet