« 2023 »

627 reports

2023-05-23 • Genians

Genians analyzed an APT37 campaign that impersonated a North Korean human-rights organization to target South Korean individuals and organizations. The report maps the attack scenario from spear-phishing through LNK-based delivery, follow-on payload execu…

#APT37 #RokRAT #LNK #T1082 #T1059.003 #T1567.002 #T1005 #T1113 #T1083 #T1204.002 #T1566.002 #T1059.005 #T1566.001 #T1598.003 #T1059.001 #T1497.001 #T1055 #T1027.010 #T1027.009 #T1027.003 #T1598.002 #T1001.002
2023-05-22 • SEKOIA

Sekoia.io analyzes Bluenoroff’s RustBucket activity as North Korea-nexus, financially motivated targeting of cryptocurrency, venture-capital, and related entities. The macOS chain installs a backdoored but functional PDF reader and requires a matching key…

#Bluenoroff #macOS #RustBucket