« 2023 »

627 reports

2023-05-12 • NSHC

NSHC’s 2022 SectorA activity summary reports seven North Korea-linked SectorA subgroups conducting both intelligence collection against South Korea-related political, diplomatic, government, research, and defector communities and financially motivated act…

#Trend #SectorA
2023-05-09 • Ecu CERT

Lazarus Operation DreamJob activity used a fake HSBC job-offer lure to deliver a native 64-bit Linux ELF downloader, expanding the campaign beyond earlier Windows and macOS targeting. The infection chain starts with a ZIP containing a deceptive file name …

#DreamJob #SmoothOperator #T1090 #T1140 #T1585.003 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1083 #T1204.002 #T1566.002 #T1132.001 #T1573.001 #T1497.003 #T1593.001 #T1584.001 #T1134.002 #T1027.009 #T1562.003 #T1546.004
2023-05-09 • Kraken Labs

Outpost24’s KrakenLabs explains a threat-actor naming convention that clusters adversaries by observed capabilities, infrastructure, victims, and TTPs rather than relying solely on another vendor’s attribution labels. The methodology uses adjective-plus-p…

#Churihyang
2023-05-08 • BBC

BBC’s Lazarus Heist episode “Big spenders” examines North Korea-linked hacking in the context of whether the country’s nuclear weapons programme can be stopped. The excerpt highlights a hacker interview-style hook—“Are you a hacker? Yes, I am.”—and places…

#Podcast #Lazarus
2023-05-03 • Chainalysis

Chainalysis attributes the Qubit/QBridge theft to North Korea-linked hackers and describes it as South Korea’s largest cryptocurrency theft of 2022, with roughly $80 million drained from the BNB-chain DeFi lending protocol. The attackers exploited QBridge…

#Qubit
2023-05-03 • KRIFANS

The IFANS report assesses North Korea’s cyber capability as a strategic asymmetric tool used for military, political, intelligence, influence, and revenue-generation objectives. It emphasizes that DPRK operations target governments, critical infrastructur…

#Trend
2023-05-01 • Checkpoint

Check Point tracks APT37-linked ROKRAT activity shifting from older HWP exploits and Office macros toward ZIP or ISO archives containing oversized LNK files that launch multi-stage infection chains. The lures focus heavily on South Korean domestic and for…

#APT37 #RokRAT #LNK