« 2024 »

654 reports

2024-10-03 • Kandji

Kandji analyzed a macOS application named OSX-PDF-Viewer after VirusTotal detections labeled it as DPRK-attributed malware and researchers noted overlap with RustBucket artifacts. The app is an ad hoc-signed Swift PDF viewer based on an old open-source pr…

#macOS #RustBucket
2024-10-03 • Securonix

Securonix describes SHROUDED#SLEEP, an ongoing campaign likely attributed to North Korea's APT37, delivering the VeilShell PowerShell backdoor against Southeast Asian targets with Cambodia as a primary focus. The infection chain begins with phishing lures…

#APT37 #VeilShell #ShroudedSleep #T1082 #T1070.004 #T1041 #T1555 #T1560 #T1112 #T1204.001 #T1059.007 #T1027 #T1204.002 #T1057 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1003 #T1033 #T1132 #T1069 #T1574.014
2024-10-01 • Chollima Group

While the scale of the IT Workers is in itself an issue, 2024 has shown that IT Workers are increasingly engaged in, or adjacent to, malicious activities that extend beyond illegal employment, including: cryptocurrency heists, malware campaigns, and extor…

#ITWorker
2024-10-01 • Bf V

Germany's security advisory warns that North Korean intelligence services use undercover remote IT workers to earn foreign currency for the regime. The activity targets companies worldwide through freelancer or remote-work arrangements and can expose empl…

#ITWorker
2024-09-29 • Truflation

Truflation's clearinghouse describes a September 2024 hack response centered on wallet tracing, blacklisting and a public bounty. The team said no user funds were compromised, but it tracked attacker-controlled wallets and reported that 1.37 million DAI w…

#Truflation
2024-09-27 • Aliyun

The source analyzes XML malware attributed to Kimsuky that uses PowerShell to download and execute an external script with a hidden window. The XML content contains hex-encoded PE data that is reconstructed into a binary, saved as xBqz.mp3, renamed as an …

#Kimsuky #XML