« 2024 »

654 reports

2024-09-17 • somedieyoung ZZ

The analysis covers a Windows LNK sample whose TTPs are assessed by the author as consistent with Kimsuky or another DPRK-based actor. The shortcut uses mshta.exe and JavaScript arguments to reach 64.49.14.181, retrieve a Base64-encoded ZIP, write it as C…

#Kimsuky #LNK
2024-09-16 • Pyongyang Papers

Pyongyang Papers links DPRK IT worker Sin Chong Min to a network of IT workers conducting activity associated with Microsoft’s Moonstone Sleet cluster. The article describes North Korean workers using fake or stolen identities, laptop farms, and remote so…

#MoonstoneSleet
2024-09-16 • Rekt

DeltaPrime Blue on Arbitrum lost $5.98 million after a compromised admin address was used to upgrade proxy contracts to a malicious implementation. The attacker inflated deposit balances across pools, made 57 withdrawals, and moved USDC, WBTC and WETH int…

#Cryptocurrency #DeltaPrime
2024-09-12 • UKOFSI

The UK OFSI advisory says UK firms are almost certainly being targeted by DPRK IT workers posing as freelance third-country technology workers to generate revenue for the North Korean regime. The workers are assessed as using online freelance platforms, f…

#ITWorker