« 2024 »

654 reports

2024-07-25 • Ahnlab

ASEC reports malicious LNK files being distributed against domestic financial companies through emails containing a URL that downloads a ZIP named as a financial-authority project information request. The archive contains a decoy PDF about virtual-currenc…

#LNK
2024-07-25 • USCISA

The joint CISA advisory attributes ongoing espionage to Andariel, also tracked as Onyx Sleet, DarkSeoul, Silent Chollima, Stonefly, and Clasiopa, under North Korea's RGB 3rd Bureau. The group targets defense, aerospace, nuclear, engineering, medical, and …

#Andariel #YARA #T1090 #T1587.001 #T1560 #T1083 #T1027 #T1567 #T1071 #T1059 #T1003 #T1190 #T1592 #T1087 #T1591 #T1596 #T1048 #T1021.002 #T1021 #T1040 #T1572 #T1595 #T1039 #T1587.004
2024-07-25 • Sakai

A Konni-themed intrusion used a ZIP lure impersonating a Bithumb cryptocurrency-exchange information update request tied to financial-authority project reporting. The archive contained a decoy PDF and a large Windows shortcut disguised as an Excel file, w…

#Konni #LNK
2024-07-20 • Quill Audits

QuillAudits analyzes the July 2024 WazirX theft, where attackers stole more than $235 million by turning a Safe multisig wallet upgrade path against the exchange. The attackers deployed a phishing contract eight days before the theft, collected the requir…

#WazirX
2024-07-19 • Liminal

Liminal says the WazirX incident affected a single imported Gnosis SAFE smart contract wallet rather than Liminal-hosted wallet infrastructure. Its investigation attributes the attack path to three compromised WazirX signer devices that injected malicious…

#Cryptocurrency #WazirX
2024-07-19 • Cyfirma

CYFIRMA's Q2 2024 APT roundup says North Korean operators intensified espionage and financially motivated activity during the quarter. The DPRK section names Kimsuky, also tracked as Springtail, targeting South Korea with the Gomir backdoor, ReconShark ac…

#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
2024-07-18 • Rekt

WazirX lost about $235 million after attackers took control of its Safe multisig wallet and drained funds to a main attack address. The source says the operators prepared with small test transactions, likely compromised two private keys, and phished two a…

#Cryptocurrency #WazirX
2024-07-19
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584