Malwarebytes analyzed a macOS variant of the Dacls RAT that it associates with Lazarus/Hidden Cobra/APT38 and detects as OSX-DaclsRAT. One observed variant downloaded a payload from loneeaglerecords[.]com into ~/Library/.mina, while related samples shared…
« Reports in 2020 »
204 reports
The Leery Turtle report profiles a financially motivated APT active since at least late 2017 against cryptocurrency exchange businesses worldwide. The group performs reconnaissance against technical and executive staff, sends decoy emails with benign atta…
Operation Flash Cobra is analyzed as Lazarus activity that begins with a malicious document using remote template injection to retrieve and execute the next-stage DOTM macro. The macro decodes embedded content, extracts an architecture-specific DLL and lu…
Objective-See analyzed a macOS variant of the Lazarus-linked Dacls RAT distributed as a TinkaOTP Apple disk image and application bundle. The initial remote infection path was unknown, but the packaging resembled earlier Lazarus activity that used trojani…
QiAnXin reported a Lazarus-attributed targeted campaign using diplomatic-relations themes and Western aerospace recruitment lures, including Boeing-themed documents, to attack specific countries. The samples used remote template injection to fetch macro-e…
IssueMakersLab reported that North Korea's RGB-D5, including Kimsuky, distributed Android APK malware to many South Korean users. The post says the malware was created with the open source AhMyth Android RAT, indicating reuse of commodity mobile RAT code …
ASEC warned that HWP malware using Encapsulated PostScript objects had increased in April 2020, including lures impersonating COVID-19 infection-control organizations and Korea Hydro & Nuclear Power recruitment notices. The attacker inserted malicious EPS…
ESRC reported a rise in Lazarus-attributed APT activity in April 2020, including spear-phishing that impersonated a blockchain software development contract and targeted people connected to cryptocurrency trading. The same activity set also included COVID…
Tencent’s 2020 analysis describes Hermit, a Tencent-named cluster linked through correlation to KONNI/SYSCON/SANNY activity, continuing operations against Korean Peninsula-related NGOs, government bodies, trade companies, and media. The group used malicio…
StrangerealIntel analyzed an APT37-themed malicious document that uses an auto-open macro to decode an embedded next-stage payload with XOR 0xFF, save it in the user profile, and launch it with a C2 URL. The second stage is a UPX-packed PE loader that che…
ESRC attributed an April 2020 APT attack to the Konni group, using a Korean-language MS Word lure themed around COVID-19 mask demand. The document prompted users to enable content; its macro then downloaded additional files from attacker infrastructure an…
VMware Carbon Black TAU traces DHS-reported HotCroissant, attributed by DHS to North Korea's Hidden Cobra/Lazarus Group, and compares it with the earlier Rifdoor RAT used in attacks dating back to 2015. HotCroissant decodes its C2 address at startup, send…
NSHC ThreatRecon found COVID-19-themed APT activity across multiple regions, with the DPRK-relevant section describing SectorA05 and SectorA07 activity against organizations affiliated with South Korea's Ministry of Foreign Affairs. The attackers used Kor…
A joint U.S. advisory from State, Treasury, Homeland Security, and the FBI described the DPRK cyber threat, which the U.S. government refers to as HIDDEN COBRA, as a risk to the international financial system and global network defenders. The advisory say…
QiAnXin RedDrip analyzed Lazarus-attributed targeting of South Korea that used COVID-19 emergency-response lures and HWP attachments impersonating regional disease-control notices. The malicious HWP files contained EPS/PostScript content that executed Pow…