« 2024 »

654 reports

2024-06-27 • Nurilab

Nurilab analyzes Gomir, a Linux variant of the GoBear backdoor linked in the source to Kimsuky activity against South Korean organizations and companies. The malware checks for an "install" command-line argument and root privileges, then persists either a…

#Kimsuky #Gomir
2024-06-25 • Alex Lab

ALEX said forensic tracing produced substantial evidence linking the May XLink/ALEX exploit to Lazarus Group. The update says the exploit address 0x418e337774d26365efeaa4700e889a9746330c4e sent funds to 0x639F61cA3E0e3fDCd654DC4A22579e7382dEBeA3, which us…

#News #AlexLab