« Reports in 2018 »

172 reports

2018-02-27 • Carbonblack

Carbon Black examined ROKRAT, also known as DOGcall, a remote access trojan used by attackers originating from North Korea. The malware is commonly delivered by loaders or carrier files such as macro-enabled Office documents, injects shellcode into proces…

#RokRAT
2018-02-13 • USCISA

DHS and FBI describe HARDRAIN as HIDDEN COBRA malware used by North Korean government actors with proxy servers to maintain access and support further exploitation. The MAR analyzes three files: two 32-bit Windows executables that act as proxy servers usi…

#HiddenCobra #HARDRAIN