« 2024 »

654 reports

2024-05-29 • USTreasury

U.S. Treasury assesses that NFT platforms are exposed to fraud, theft, money laundering, and sanctions-evasion risks, with far less evidence to date of terrorist or proliferation-financing misuse. The assessment says criminals can exploit weak cybersecuri…

#NFT
2024-05-28 • Hauri

Hauri reports a phishing campaign impersonating Naver login pages to steal credentials from Korean users through email distribution. The phishing site checked submitted credentials against naver.com to verify whether the victim had entered valid account i…

#Kimsuky #Phishing
2024-05-23 • Ahnlab

AhnLab ASEC describes APT attacks that rely on cloud services such as Google Drive, OneDrive, and Dropbox to host malicious scripts, decoy documents, and RAT payloads. The infection chain uses lure files such as LNK shortcuts and cloud-hosted components t…

#LNK #XenoRAT
2024-05-22 • errbody

The GitHub repository is a small DPRK research collection for malware analysis tools associated with North Korea linked groups. The captured repository listing names folders for Kimsuky/APT43 with DropBox related material and Lazarus/APT38 with Comebacker…

#Kimsuky #Scarcruft #Konni #RokRAT
2024-05-21 • Securonix

CLOUD#REVERSER uses phishing-delivered ZIP archives and an executable disguised as an Excel file to install a multi-stage VBScript and PowerShell infection chain. The malware persists through scheduled tasks that mimic Google update jobs, repeatedly execu…

#Phishing #T1082 #T1059.003 #T1070.004 #T1041 #T1560 #T1555.003 #T1547.001 #T1059.001 #T1027.010 #CloudReverser