« 2024 »

654 reports

2024-03-21 • Secu I

Secui STIC reports an APT37-style LNK campaign that used a North Korea-themed contribution article lure to deliver RokRAT. The ZIP archive contained normal PDF decoys and a malicious LNK file; when opened, the shortcut launched hidden PowerShell, extracte…

#APT37 #RokRAT #LNK #T1082 #T1560 #T1497 #T1036 #T1027 #T1071 #T1057 #T1059.001 #T1059 #T1003 #T1548 #T1203 #T1564.001 #T1106 #T1573 #T1070 #T1033 #T1485 #T1012 #T1202 #T1564.003 #T1564 #T1027.004
2024-03-18 • Securonix

Securonix tracks DEEP#GOSU as a multi-stage campaign likely associated with Kimsuky and aimed at South Korean victims. The infection chain begins with a ZIP-delivered PDF-themed LNK file that extracts and opens an embedded Korean PDF lure while running Po…

#Kimsuky #LNK #DeepGosu #T1082 #T1567.002 #T1140 #T1070.004 #T1041 #T1115 #T1083 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1057 #T1059.005 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1219 #T1027.010 #T1573 #T1047
2024-03-17 • Cyberpoking

Cyberpoking publishes a YARA rule for the SiennaPurple variant of H0lyGh0st ransomware, an actor and malware family described as having ties to the DPRK-nexus Lazarus group. The rule matches strings from SiennaPurple binaries, including a PDB path, ransom…

#H0lyGh0st #YARA
2024-03-12 • somedieyoung ZZ

The source analyzes a Kimsuky sample named like a Korean software security checklist for developers, using a double extension to make a VBScript look like an Excel macro file. The VBScript creates shell and file-system objects, writes large Base64 payload…

#Kimsuky #YARA