« 2024 »

654 reports

2024-11-04 • Rewterz

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group that mainly targets South Korea and has also operated against Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and Middle Eastern targets. The advisory …

#APT37 #RokRAT
2024-11-04 • Zscaler

North Korean operators behind Contagious Interview and WageMole continued using fake developer hiring activity to steal data and support remote job fraud in Western countries. Zscaler observed updated BeaverTail JavaScript and InvisibleFerret Python paylo…

#ContagiousInterview #Wagemole #BeaverTail #InvisibleFerret #T1027.013 #T1082 #T1005 #T1041 #T1071.001 #T1083 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1071.002 #T1560.001
2024-11-04 • Genians

Genians analyzes APT37 reconnaissance activity against South Korea, including collection of target IP address, location, web browser, and operating-system details before endpoint compromise. The report links the activity to prepared threat infrastructure …

#APT37
2024-11-01 • Rewterz

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group that mainly targets South Korea and has also operated across Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and the Middle East. The advisory links AP…

#APT37 #RokRAT
2024-10-30 • Rewterz

This APT group was detected targeting the Russian diplomatic sector in January 2022, employing a spear phishing theme for New Year's Eve festivities as bait. The North Korean hacker group distributes Konni RAT via phishing messages or emails. KONNI has be…

#Konni
2024-10-30 • Trellix

DPRK-aligned APT macOS activity In recent years, the Lazarus Group, a North Korean state-sponsored APT group , has intensified its focus on macOS, marking a significant shift in the macOS threat landscape. They employed advanced phishing campaigns themed …

#macOS #Lazarus