« 2024 »

654 reports

2024-02-22 • Secu I

SECUI analyzes a Kimsuky reconnaissance malware variant that shifted delivery from earlier LNK files to a compiled HTML Help file. The CHM lure appears to contain Bitcoin key themed content and executes embedded scripts through hh.exe, decompiling files i…

#CHM #Kimsuky
2024-02-21 • KRCERT

KrCERT warned that an improper-authentication vulnerability in MLSoft Tgate could let attackers gain administrator privileges and potentially deploy malware. Organizations using Tgate should update through MLSoft, while unsupported v2.0 and earlier instal…

#Tgate
2024-02-21 • Crowd Strike

CrowdStrike's 2024 Global Threat Report documents North Korean adversary activity as maintaining a high operational tempo during 2023, with financially motivated cryptocurrency theft and intelligence collection against South Korean and Western organizatio…

#Trend #Chollima
2024-02-21 • Mandiant

This Defender's Advantage podcast episode features Mandiant analyst Michael Barnhart discussing DPRK use of IT workers to gain access to enterprises. The source frames the activity as an enterprise access risk rather than conventional malware delivery, wi…

#Podcast #ITWorker
2024-02-20 • Phylum

Phylum found a malicious npm package, execution-time-async, that copied the legitimate execution-time profiler package but hid obfuscated JavaScript in a test file loaded from index.js. The code stole browser credentials, cryptocurrency extension data, an…

#NPM