« 2023 »

627 reports

2023-02-27 • Ahnlab

AhnLab analyzed a Lazarus intrusion that abused a vulnerability in certificate-related software widely used by South Korean public institutions and universities. The victim had previously been compromised by Lazarus in May 2022 and was reinfected through …

#BYOVD #Lazardoor #Lazarus #T1059.003 #T1070.004 #T1587.001 #T1071.001 #T1046 #T1102 #T1562.001 #T1203 #T1588.002 #T1070.006 #T1068 #T1070 #T1210 #T1587.004
2023-02-27 • Zero Memory Ex

The GitHub project describes a proof-of-concept program modeled on APT38/North Korea-backed social-engineering tactics against security researchers. The source says attackers trick researchers into collaborating through a malicious Microsoft Visual Studio…

#APT38 #DreamJob
2023-02-23 • Ahnlab

ASEC analyzed a Magniber relaunch mechanism in MSI-distributed samples aimed at Chrome and Edge users through typosquatting. The ransomware injects payloads into user processes and randomly chooses between immediate encryption and persistence setup. For p…

#Ransomware #Magniber
2023-02-23 • ESET

ESET identified WinorDLL64 as a Wslink payload and assessed with low confidence that it is connected to Lazarus based on South Korean victim telemetry, timing, development-environment overlap, and behavior/code similarities with GhostSecret and Bankshot-r…

#Wslink #T1082 #T1005 #T1070.004 #T1587.001 #T1083 #T1057 #T1059.001 #T1135 #T1049 #T1016 #T1087.001 #T1134.002 #T1614 #T1106 #T1614.001 #T1033 #T1560.002 #T1012 #T1087.002 #T1531
2023-02-19 • Tribal Sec

The Substack overview profiles Lazarus as a North Korean state-linked threat group also tracked as Hidden Cobra or Zinc, with subgroups such as Andariel and BlueNoroff and reported overlaps with APT37 and Kimsuky. It summarizes major operations including …

#Trend