« 2024 »

654 reports

2024-04-19 • KRCERT

KrCERT published emergency threat mitigation guidance for OfficeKeeper servers after suspicious uploaded PHP files and abnormal storage behavior were identified. Administrators are advised to inspect /home/storage/ and OfficeKeeper storage paths for web s…

#OfficeKeeper
2024-04-17 • ENKI

ENKI says a North Korea-linked attempt against its security researcher used social engineering around Chrome exploit collaboration to deliver an MHTML lure named Chrome_85_RCE_Full_Exploit_Code.mht. The file was crafted to push the victim toward Internet …

#DreamJob
2024-04-17 • Attack IQ

Lazarus Group's Operation Sharpshooter targeted more than 80 organizations, especially in finance, energy, and defense, during activity reported between October and November 2018. The campaign used a malicious Microsoft Office document to deploy the Risin…

#Sharpshooter
2024-04-10 • somedieyoung ZZ

Kimsuky targeted the Embassy of the Republic of Korea in China with a malicious Windows shortcut disguised as a familiar document. The LNK runs hidden PowerShell, locates a hardcoded shortcut size, extracts embedded bytes, launches the dropped payload, an…

#Kimsuky #LNK