« 2025 »

778 reports

2025-01-14 • Sec AI

SecAI analyzed a Kimsuky DOCX infection chain in which the document retrieves a malicious DOTM template from ms-work.com-info.store and runs its macro. The macro decrypts and drops a DLL, then calls an exported function that downloads another DLL payload …

#Kimsuky
2025-01-12 • Hauri

HAURI describes APT37 reconnaissance phishing against people connected to North Korea issues and defector communities. The attack embeds an IMG tag in email so that opening the message automatically reaches a phishing site, while compromised legitimate Ko…

#Phishing #APT37
2025-01-09 • Zeroshadow

ZeroShadow describes a DPRK Contagious Interview campaign that impersonated the Willo video interview platform to target cryptocurrency workers with fake recruiter outreach. Victims were moved from job messages to a lookalike interview site, where a stage…

#ContagiousInterview
2025-01-09 • Sec AI

SecAI analyzed a Kimsuky JSE sample that used obfuscated JavaScript to drop a JPG decoy and an encrypted PowerShell payload. The PowerShell stage decrypted embedded data into an executable file, launched it with a VMP-packed PE payload, and connected to t…

#Kimsuky #JSE
2025-01-08 • Ahnlab

AhnLab's December 2024 domestic APT trend report summarizes attacks observed against Korean targets through the vendor's monitoring infrastructure. The report classifies the month's intrusions by penetration type and finds spear phishing to be the dominan…

#Trend #LNK