AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178)
2024-10-15 • Ahnlab •
They have previously targeted specific individuals such as North Korean defectors and experts in North Korean affairs using hacking emails, Android app package file (.apk), and IE vulnerabilities. The North Korean threat actor TA-RedAnt (also known as RedEyes, ScarCruft, Group123, APT37, etc.) is behind this operation. TA-RedAnt exploited this vulnerability to trick victims into downloading malware on their desktops with the toast ad program installed. This vulnerability is exploited when the ad program downloads and renders the ad content.
Related Actors
Related Reports
Shares tags: RokRAT, CVE-2024-38178, CodeonToast • Same author: Ahnlab • Published within a week
Shares tag: TA-RedAnt • Same author: Ahnlab
Shares tag: TA-RedAnt • Same author: Ahnlab
Shares tag: TA-RedAnt • Same author: Ahnlab
Shares tag: TA-RedAnt • Same author: Ahnlab
2024-10-23 •
40% Match
Analyzing the North Korean hacking group APT37 (Scarcruft) attack with CVE-2024-38178 : Operation Code On Toast
Igloo
Shares tags: CVE-2024-38178, CodeonToast • Published within a month