« 2024 »

654 reports

2024-07-15 • Darkatlas

Dark Atlas analyzed Kimsuky's TrollAgent stealer campaign against South Korean targets, with samples compiled in late 2023 and activity tracked from January 2024. The installer used digital signatures from SGA Solutions and D2innovation, dropped a Go-base…

#Kimsuky #TrollAgent #T1082 #T1059.003 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1083 #T1036 #T1555.003 #T1057 #T1518.001 #T1539 #T1027.002 #T1016 #T1087.001 #T1218.011
2024-07-12 • Threat Book

Konni activity against South Korean targets used spear-phishing lures and LNK files to start a compiled AutoIt payload with low detection coverage, according to the archived source. The reporting highlights compromised-site payload hosting, Korean RTP eng…

#Konni
2024-07-12 • Coin Stats

CoinStats attributed its June 22, 2024 wallet breach to Lazarus Group or a related nation-state-level organization after reviewing evidence with law enforcement and security researchers. The attacker gained unauthorized access across CoinStats infrastruct…

#News #CoinStats