« 2024 »

654 reports

2024-09-12 • Cyfirma

CYFIRMA profiles Kimsuky as a North Korean hacking group active since at least 2018 and engaged in espionage and financially motivated cybercrime aligned with North Korean state interests. The profile lists target exposure across South Korea, the United S…

#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
2024-09-11 • Rekt

Indodax lost roughly $25.22 million on September 10 after attackers initiated withdrawals across Ethereum, Polygon, Tron, Bitcoin, and other chains. Cyvers reported suspicious transactions from exchange wallets, while SlowMist assessed that the activity d…

#Cryptocurrency #Indodax2
2024-09-10 • SBT

Security Blue Team uses the KnowBe4 fake IT-worker incident to explain how North Korean operators can combine stolen identities, AI-enhanced profile images and remote hiring workflows to gain insider access. The excerpt says the impostor passed hiring che…

#ITWorker
2024-09-09 • Paloalto Networks

Unit 42 maps North Korean cyber activity to RGB-linked clusters rather than treating all public reporting as a single Lazarus label. The assessment separates Alluring Pisces, Gleaming Pisces, Jumpy Pisces, Selective Pisces, Slow Pisces, and Sparkling Pisc…

#SelectivePisces #SmoothOperator #RustBucket #CollectionRAT #KANDYKORN #ObjCShellz #Comebacker #SlowPisces #JumpyPisces #AlluringPisces #Fullhouse #GleamingPisces #OdicLoader #POOLRAT #PondRAT #SparklingPisces
2024-09-03 • Sentinel One

SentinelOne describes North Korean IT workers using fraudulent employment to enter U.S. companies, earn revenue for the DPRK, and create security exposure inside corporate networks. The report cites the August 2024 Justice Department case against Matthew …

#Trend #ITWorker
2024-09-12
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003