« 2024 »

654 reports

2024-11-26 • Secure Works

Sophos profiles NICKEL TAPESTRY as a North Korea-linked fraudulent IT worker activity set, aligned with names such as DPRK IT Workers, Famous Chollima, Jasper Sleet, Purpledelta, Storm-0287, UNC5267, and Wagemole. The activity comprises multiple clusters …

#NickelTapestry
2024-11-26 • Ahnlab

AhnLab describes how threat actors use proxy and tunneling tools after compromise to expose RDP access from systems hidden behind NAT. The report highlights Ngrok commands that publish port 3389, Plink SSH tunneling used after Exchange exploitation in a L…

#Andariel #Kimsuky #Lazarus
2024-11-26 • Sec AI

Kimsuky, also known as APT43, APT-Q-2, Velvet Chollima, Black Banshee, Thallium, Sparkling Pisces, etc., has been operating since 2012 and is supported by the North Korean government. Recently, SecAI has detected a series of targeted attacks launched by K…

#Kimsuky #LNK
2024-11-23 • screaminggoat

The excerpt catalogs North Korean IT worker activity as a DPRK revenue-generation and espionage threat tied to entities such as the 313 General Bureau, Pyongyang technology organizations, Yanbian Silverstar, Volasys Silver Star, and Chinyong. It lists nam…

#ITWorker
2024-11-22 • Ahnlab

ASEC reports that attackers in 2024 increasingly used Microsoft Management Console MSC files as Office document malware declined. One MSC class abuses CVE-2024-43572 in apds.dll, while another uses MMC Console Taskpad entries to run commands from files di…

#Trend #Kimsuky #MSC
2024-11-21 • Secure Works

Sophos profiles NICKEL JUNIPER as a North Korea-linked espionage group, also associated with Konni, Opal Sleet, and OSMIUM. The group targets South Korea and Russia, especially government entities and the cryptocurrency industry, with both intelligence-ga…

#NickelJuniper
2024-11-21 • Rewterz

This APT group has been associated with other threat actor groups, including Bluenoroff and Andariel, believed to be subgroups or closely aligned with Lazarus. One of their recent campaigns, "Dream Job," specifically targets cryptocurrency-adjacent entiti…

#Lazarus