« 2023 »

627 reports

2023-01-18 • Qihoo360

360's 2022 global APT research report assessed that APT activity remained highly active under geopolitical pressure. The report counted 742 public APT reports in 2022 involving 141 groups, including 54 first-disclosed organizations. It mapped active group…

#Trend
2023-01-18 • Greg Lesewich

The source examines the macOS port of the DPRK-linked Dacls/MATA malware family and explains how to build YARA rules from non-Objective-C binary traits. The analysis focuses on exported MataNet function names, wolfSSL-linked symbols, HTTP header strings, …

#YARA #Dacls #MATA
2023-01-17 • Any Run

WannaCry is characterized as a network cryptoworm ransomware that spread through vulnerable SMB implementations in older Windows systems instead of relying mainly on malicious email attachments. After infection, it encrypted files, directed victims to a B…

#WannaCry
2023-01-17 • Any Run

WannaCry, sometimes also called WCry or WanaCryptor is ransomware malware, meaning that it encrypts files of its victims and demands a payment to restore the stolen information, usually in bitcoin with ransom amounts ranging from $300 to $600 equivalents.…

#WannaCry
2023-01-16 • Greg Lesewich

The notebook walks through macOS malware analysis and YARA development using the CloudMensis spyware component as the specimen, noting prior ESET disclosure and Volexity attribution to APT37. The analysis identifies a universal Mach-O binary with x86_64 a…

#YARA #APT37 #CloudMensis #RokRAT