« Reports in 2018 »

172 reports

2018-12-23 • Cyberfox

The analysis examines a malicious Word document macro that the author says was associated with Lazarus tooling by archive context and flagged by Thor's APT_MalDoc_SharpShooter_Lazarus_Campaign_Dec18_1 YARA rule. The macro was slightly obfuscated and defin…

#APT38
2018-12-13 • Mcafee

McAfee documented Operation Sharpshooter, a global campaign against nuclear, defense, energy, financial, defense, and government related organizations. Malicious job description documents with Korean-language metadata used macros and embedded shellcode to…

#Sharpshooter #RisingSun
2018-12-12 • fboldewin

Hidden Cobra, also known as Lazarus or APT38, is tied in the PDF to FASTCash activity against banking payment-switch infrastructure. The recovered analysis describes a 2018 incident where attackers manipulated transaction response messages on an IBM AIX P…

#FASTCash #AIX
2018-12-10 • Fireeye

FireEye and Mandiant researchers introduce APT38 as a North Korea-linked financial intrusion group that operates separately from ordinary espionage clusters. The talk explains how the group targets banks and financial infrastructure, combines long dwell t…

#APT38 #Youtube