« 2023 »

627 reports

2023-04-17 • BBC

BBC’s Lazarus Heist episode “False flags” covers the unmasking of the Olympic hackers and references the political “bromance” around “beautiful letters.” The source excerpt is a short BBC Sounds listing rather than a technical analysis, so it does not sup…

#Podcast #Lazarus
2023-04-14 • Certi K

CertiK analyzed the April 2023 GDAC exchange compromise, assessing it as highly likely a private-key compromise that caused about $13 million in cryptocurrency losses, or 23% of GDAC's holdings. The incident likely began on Ethereum around 18:36 UTC on 8 …

#Cryptocurrency #Suspicious #GDAC
2023-04-14 • Attack IQ

The compromised binary in this case is a software-based Private Automatic Branch Exchange (PABX) Voice over Internet Protocol (VoIP) phone system developed by the company 3CX, and it was compromised through a supply chain attack suspected to have the invo…

#SupplyChain #3CXDesktopApp #SmoothOperator #T1082 #T1071.001 #T1057 #T1105 #T1055 #T1620 #T1049 #T1087.001 #T1070.006 #T1574.001 #T1543.003 #T1012 #T1069.001 #T1016.001 #T1547.002
2023-04-13 • Threat Book

ThreatBook's 2022 APT activity report includes a DPRK section covering Lazarus, Kimsuky, and Group123 alongside other regional threat actors. Its Lazarus case study focuses on poisoned IDA Pro 7.5 installers aimed at security researchers, where a maliciou…

#Trend
2023-04-12 • PWC

PwC's 2022 threat retrospective is a broad landscape report, but its DPRK-relevant section notes that North Korea-based threat actors intensified financially motivated operations. The excerpt says these actors continued targeting financial services, crypt…

#Trend #SnatchCrypto #BlackDev2 #BlackArtemis #BlackAlicanto #T1140 #T1560 #T1204.002 #T1071 #T1547.001 #T1053.005 #T1059.001 #T1219 #T1574.002 #T1133 #T1557 #T1090.001 #T1560.001 #T1021.002 #T1543.003 #T1505.003 #T1048.002
2023-04-11 • Neptune Mutual

Terraport Finance lost about $3.9 million on April 10, 2023 after its Terraport Liquidity wallet was breached and drained of LUNC, TERRA, and USTC tokens. The source says the root cause was still unknown, but two attack transactions moved roughly 15.1 bil…

#Terraport