« 2024 »

654 reports

2024-02-16 • SOCRadar

SOCRadar profiles ScarCruft, also known as APT37 or Reaper, as a North Korea associated espionage group active since 2012 and primarily focused on South Korea and other Asian targets linked to Pyongyang's interests. The source describes spear phishing, wa…

#Scarcruft
2024-02-15 • Ahnlab

AhnLab's K-CTI 2024 presentation emphasized that identifying threat actors and understanding their strategies are central to modern cyber threat intelligence. The talk explained that vendors use different naming and management systems, including MITRE ATT…

#Youtube #TA-Ant
2024-02-14 • Microsoft

Emerald Sleet’s use of LLMs has been in support of this activity and involved research into think tanks and experts on North Korea, as well as the generation of content likely to be used in spear-phishing campaigns. Their recent operations relied on spear…

#EmeraldSleet
2024-02-08 • S2W

S2W Talon analyzed Troll Stealer, a Go-based infostealer distributed from a Korean security program download flow that redirected users to installers for products such as TrustPKI and NX_PRNMAN. Only some installers on the site were modified, and the drop…

#Kimsuky #D2Innovation #TrollStealer #T1082 #T1059.003 #T1005 #T1041 #T1113 #T1560 #T1071.001 #T1083 #T1204.002 #T1555.003 #T1057 #T1518.001 #T1539 #T1059.001 #T1027.002 #T1016 #T1087.001 #T1588.004
2024-02-07 • S2W

S2W Talon assesses that Kimsuky or a closely related cluster distributed Troll Stealer through installers masquerading as SGA Solutions security software on a Korean download page. The dropper and decoy installer were signed with a valid D2innovation Co.,…

#Kimsuky #D2Innovation #TrollStealer #T1082 #T1059.003 #T1005 #T1041 #T1113 #T1560 #T1071.001 #T1083 #T1204.002 #T1555.003 #T1057 #T1518.001 #T1539 #T1059.001 #T1027.002 #T1016 #T1087.001 #T1588.004