« 2024 »

654 reports

2024-12-13 • 0xmh1

The source explains how Korean-language artifacts can support DPRK malware and phishing attribution when treated as one signal among others, not as standalone proof. It highlights wording and grammar that sound North Korean or unnatural to South Korean sp…

2024-12-09 • Rewterz

Rewterz describes active APT37, ScarCruft, or RedEyes indicators tied to North Korean espionage activity, with recent reporting that the group expanded from CHM malware disguised as a Korean financial-company security email to RokRAT delivery through LNK …

#APT37
2024-12-09 • Sec AI

SecAI analyzes a Kimsuky XLS-based attack that uses a macro to decrypt and drop msload.exe under the user's Microsoft Templates directory before launching it with the parameter QCvt5676hZXbg. The malware branches execution based on parameters, copies itse…

#Kimsuky