« 2023 »

627 reports

2023-02-03 • Ahnlab

AhnLab reports that Kimsuky-linked malicious documents previously seen against security-sector personnel were also being distributed to broadcasting and general enterprise users. The lure documents, including files resembling KBS interview questions and a…

#Kimsuky
2023-02-02 • With Secure

WithSecure attributes the Q4 2022 “No Pineapple” intrusion with high confidence to Lazarus Group, targeting public and private research organizations, medical research, energy-sector entities, and their supply chain for likely intelligence collection. Ini…

#Whitepaper #NoPineapple #DTrack #GREASE #Zimbra #T1082 #T1119 #T1070.004 #T1041 #T1560 #T1071.001 #T1083 #T1071 #T1057 #T1053.005 #T1036.005 #T1059 #T1078 #T1190 #T1049 #T1016 #T1018 #T1003.001 #T1021.001 #T1106 #T1090.001 #T1074 #T1553 #T1033 #T1569.002 #T1090.002 #T1012 #T1087.002 #T1114.002 #T1505.003 #T1556 #T1037.005 #T1136 #T1070.007 #T1587.002
2023-01-31 • Elliptic

As a result, Elliptic was the first to attribute the hack to APT38 – otherwise known as The Lazarus Group – within days of the hack. They were also able to complete a detailed analysis of this exploit’s characteristics, as well as subsequent laundering ty…

#Cryptocurrency #Harmony
2023-01-31 • ESET

ESET’s T3 2022 APT activity reporting notes that North Korea-aligned groups remained active against cryptocurrency firms and exchanges in multiple regions. The DPRK-linked activity relied on older exploits to compromise targets, while Kimsuky continued op…

#Trend #T1102.002 #T1090 #T1567.002 #T1113 #T1555 #T1560 #T1195.002 #T1027 #T1204.002 #T1555.003 #T1567 #T1071 #T1204 #T1566.001 #T1566 #T1102 #T1195 #T1003 #T1553.002 #T1574.002 #T1027.002 #T1090.003 #T1218 #T1190 #T1574 #T1027.007 #T1027.006 #T1560.001 #T1071.004 #T1553 #T1505.003 #T1584 #T1218.001 #T1505 #T1584.006 #T1484.001 #T1484
2023-01-30 • Somansa

Somansa analyzed document-based malware attributed to the North Korean Konni group, which has targeted South Korea and other regions since 2017. The report says Konni used HWP documents in earlier attacks against Korean companies and institutions, but shi…

#Konni