« 2023 »

627 reports

2023-04-27 • Kaspersky

DTrack is a backdoor that has been used by Andariel (aka StonedFly and Silent Chollima), a subset of Lazarus, for almost a decade in a wide variety of attacks, including deploying ransomware as well as espionage malware. We observed a Lazarus campaign, ac…

#Trend #Andariel #Scarcruft
2023-04-26 • Attack IQ

AttackIQ released emulations of Kimsuky reconnaissance and espionage operations, reflecting activity against South Korean political, government, military, reunification, security, and nuclear power-related targets. The emulated chains include CHM files de…

#Kimsuky #T1082 #T1140 #T1041 #T1071.001 #T1115 #T1083 #T1056.001 #T1057 #T1518.001 #T1547.001 #T1053.005 #T1105 #T1087 #T1016 #T1074.001 #T1218.011 #T1218.010 #T1047 #T1033 #T1048.002