« 2024 »

654 reports

2024-08-08 • Ahnlab

AhnLab's July 2024 domestic APT trend report summarizes monitored attacks against South Korean targets and includes indicators such as related domains, URLs, and IP addresses. The report highlights spear phishing as a prominent initial access method, expl…

#Trend #LNK
2024-08-05 • KRNCSC

A joint South Korean cyber security advisory warns that North Korean hacking groups are targeting the construction and machinery sectors to steal technical information. The advisory attributes the activity to Kimsuky and Andariel under the Reconnaissance …

#Andariel #Kimsuky #TrollAgent #DoraRAT #T1119 #T1005 #T1041 #T1113 #T1071.001 #T1083 #T1036 #T1204.002 #T1195 #T1027.002 #T1189 #T1573.002 #T1074.001 #T1217
2024-07-31 • Attack IQ

On December 11, 2023, Cisco Talos reported the discovery of an activity led by Andariel, a North Korean state-sponsored known to be a subgroup of the notorious Lazarus group, which employed three new DLang-based malware families. This activity consists of…

#Andariel #Blacksmith #T1082 #T1083 #T1057 #T1518.001 #T1003 #T1105 #T1049 #T1098 #T1087 #T1016 #T1018 #T1003.001 #T1562 #T1047 #T1136.001 #T1033 #T1543.003 #T1012 #T1069 #T1654