« 2024 »

654 reports

2024-08-14 • Hauri

Hauri's advisory provides defensive checks for suspected exploitation or misuse of vaccine management servers. It instructs administrators to query management-server logs for suspicious program execution strings such as PowerShell, cmd, mshta, winhost, ta…

#ViRobot
2024-08-14 • somedieyoung ZZ

The analysis examines a 2019 Kimsuky sample disguised as a Korean-language HWP quotation document with a double extension ending in .exe. The loader drops a decoy HWP file and a DLL named NewAct.dat, then uses regsvr32 to register the DLL. The DLL checks …

#Kimsuky
2024-08-12 • Crowd Strike

Famous Chollima is a North Korea-linked, state-sponsored adversary active since at least 2018 and formerly tracked by CrowdStrike as the BadClone activity cluster. CrowdStrike characterizes the group’s main objective as financial gain through illicit free…

#FamousChollima