« 2024 »

654 reports

2024-12-31 • Rewterz

This APT group has been associated with other threat actor groups, including Bluenoroff and Andariel, believed to be subgroups or closely aligned with Lazarus. One of their recent campaigns, "Dream Job," specifically targets cryptocurrency-adjacent entiti…

#Lazarus
2024-12-30 • Mamun

The source describes an APT38 or Lazarus-attributed social-engineering operation that targeted a CEO through Discord and pushed a fake online meeting download. The download flow used a passcode-protected page and delivered a small macOS DMG containing a B…

#APT38 #macOS
2024-12-28 • screaminggoat

This Andariel profile identifies the DPRK-linked group as Lab 110 / 3rd Bureau of the Reconnaissance General Bureau and catalogs its aliases, relationships, exploited vulnerabilities, and reporting history. The page maps Andariel to aliases such as APT45,…

#Andariel
2024-12-27 • Picus Security

Picus profiles Kimsuky as a North Korean espionage actor active since at least 2012 and tracked under aliases including Black Banshee, Velvet Chollima, THALLIUM and Emerald Sleet. The source describes targeting of South Korean government, think-tank, defe…

#Kimsuky #GoldDragon #xRAT #RandomQuery #T1082 #T1560 #T1071.001 #T1056.001 #T1059.004 #T1027 #T1059.005 #T1566.001 #T1547.001 #T1059.001 #T1003 #T1219 #T1055 #T1573.001 #T1074.001 #T1562.004 #T1048 #T1114.003
2024-12-26 • KRMOFA

South Korea's Ministry of Foreign Affairs announced independent sanctions against 15 North Korean IT workers and one related entity for foreign-currency earning activity tied to cyber operations and weapons funding. The statement says North Korea continue…

#Sanctions #ITWorker
2024-12-24 • Rekt

Rekt reported that DPRK-linked wallets were observed trading on Hyperliquid, raising concern that North Korean actors were testing the protocol before a possible attack. The article highlights Hyperliquid's risk profile at the time: more than $2 billion i…

#Hyperliquid