« 2024 »

654 reports

2024-12-24 • Sec AI

SecAI analyzed a Kimsuky MSC lure that opened a forged document prompt, then released a PE file and encrypted configuration data for follow-on execution. The embedded code downloaded a decoy document and malicious components into user directories, created…

#Kimsuky #MSC
2024-12-23 • Rewterz

This APT group was detected targeting the Russian diplomatic sector in January 2022, employing a spear phishing theme for New Year's Eve festivities as bait. The North Korean hacker group distributes Konni RAT via phishing messages or emails. KONNI has be…

#Konni
2024-12-20 • Rewterz

Lazarus is described as a North Korea-linked threat actor active since at least 2009, with activity spanning South Korea, the United States, Japan, and other countries. The excerpt says the group has targeted financial institutions, government agencies, m…

#Lazarus
2024-12-19 • Spur

Spur released a list of roughly 2,400 Astrill VPN IP addresses active as of December 19, 2024 because DPRK-linked remote worker personas have used the service to hide their locations. The post says intelligence and threat-analysis teams have observed Nort…

#ITWorker
2024-12-18 • Sec AI

SecAI analyzed a Kimsuky ISO lure that masqueraded as RapportSetup and executed a malicious LNK and BAT script while also launching IBM Trusteer-branded legitimate software as cover. The BAT script checked for Avast and Kaspersky processes, then used curl…

#Kimsuky #ISO