« 2023 »

627 reports

2023-03-14 • Qianxin

Qianxin profiles Lazarus Group, also tracked as APT-Q-1, as a North Korea-linked threat group active since at least 2009 with espionage and financially motivated operations. The profile describes spear-phishing, watering-hole activity, SMB exploitation, l…

#APT-Q-1
2023-03-14 • Secu I

A spear-phishing campaign targeted South Korean organizations related to North Korea by impersonating a cyber safety bureau email and attaching a ZIP archive containing a malicious CHM help file. Opening the CHM displayed legitimate-looking legal content …

#CHM #Kimsuky
2023-03-13 • KRCERT

KR-CERT advised organizations and end users to update YettieSoft VestCert and MLSoft TCO!stream after the vendors released fixes for remote code execution vulnerabilities in the financial security products. The advisory warns that attackers could exploit …

#VestCert #TCO!Stream
2023-03-08 • Crowd Strike

LABYRINTH CHOLLIMA is a DPRK-nexus adversary that CrowdStrike says has been active since at least 2009 and is likely affiliated with Bureau 121 of North Korea's Reconnaissance General Bureau. The profile ties the cluster to multiple community identifiers,…

#LabyrinthChollima