« 2023 »

627 reports

2023-10-27 • Ahnlab

AhnLab ASEC analyzed malicious Hangul documents aimed at people in defense, media, unification, education, and broadcasting related fields. One cluster used oversized embedded OLE objects to make nearly any click in the document trigger a connection to at…

#OLE
2023-10-27 • Kaspersky

Lazarus compromised a software vendor through unpatched legitimate software and continued exploiting that vendor’s software while targeting other software makers, suggesting interest in source code theft or supply-chain tampering. The campaign deployed SI…

#LPEClient #SIGNBT #T1082 #T1140 #T1041 #T1113 #T1071.001 #T1083 #T1057 #T1620 #T1574.002 #T1027.002 #T1573.001 #T1203 #T1189 #T1132.002 #T1003.001 #T1027.001 #T1547.012
2023-10-26 • Reversing Labs

The LASCON session abstract covers the 3CX software supply chain attack in which a VoIP vendor shipped malicious code to thousands of customers. Some affected customers later reported compromises inside their own environments. The abstract frames the inci…

#Youtube #3CXDesktopApp
2023-10-26 • ESET

The most active Lazarus scheme observed was Operation DreamJob, luring targets with fake job offers for lucrative positions. North Korea-aligned groups continued to focus on Japan, South Korea, and South Korea-focused entities, employing carefully crafted…

#Trend