« 2025 »

778 reports

2025-01-07 • Rewterz

This APT group was detected targeting the Russian diplomatic sector in January 2022, employing a spear phishing theme for New Year's Eve festivities as bait. The North Korean hacker group distributes Konni RAT via phishing messages or emails. KONNI has be…

#Konni
2025-01-02 • Sec AI

SecAI analyzes a malicious CHM sample linked to Kimsuky activity, showing how the file uses an embedded HTML page and script execution to launch VBS code. The infection chain runs a VBS script from the same directory, executes a second VBS payload stored …

#CHM #Kimsuky
2025-01-02 • Ahnlab

AhnLab describes detection of a Play ransomware intrusion using EDR telemetry and notes that Play, also known as Balloonfly or PlayCrypt, has attacked more than 300 organizations since 2022. The report highlights double-extortion behavior through data the…

#Andariel #Ransomware #Play #T1046 #T1219 #T1562.001 #T1486 #T1018 #T1657 #T1003.001 #T1048.003 #T1560.001 #T1033 #T1087.002 #T1570 #T1069.001 #T1069.002 #T1572 #T1615 #T1482
2025-01-01 • Ahnlab

AhnLab describes Play ransomware intrusion tradecraft and notes Palo Alto Unit42 reporting that linked Play activity to Andariel through shared infrastructure after Andariel used Sliver and DTrack for information theft. The excerpt states that Play operat…

#Andariel #Ransomware #Play #T1046 #T1219 #T1562.001 #T1486 #T1018 #T1657 #T1003.001 #T1048.003 #T1560.001 #T1033 #T1087.002 #T1570 #T1069.001 #T1069.002 #T1572 #T1615 #T1482