Lexfo’s Lazarus Constellation white paper summarizes Lazarus as a North Korea-linked APT whose activity has been traced back to 2007 and formally clustered in the 2016 Operation Blockbuster research. The excerpt emphasizes the group’s reuse of large code …
« Reports in 2020 »
204 reports
PwC describes Black Banshee, also known as Kimsuky, as a North Korea-based espionage actor whose 2019 activity can be grouped into interlinked clusters tied by infrastructure, tradecraft, shared indicators, and targeting. The WildCommand cluster connected…
Tencent’s 2019 global APT report is a broad landscape review, but its DPRK-relevant sections describe East Asian activity from DarkHotel, Higaisa, Lazarus, Group123/APT37, and related Korean Peninsula-linked actors. The report says Lazarus pursued economi…
Igloo summarizes Lazarus as a suspected North Korean state-backed group active against domestic Korean targets, with historical links cited to Operation Troy, Sony Pictures, Hidden Cobra, Andariel, and BlueNoroff. The analyzed cases center on malicious Ha…
A malware analysis write-up describes a Kimsuky variant targeting South Korea with a resume-themed executable named like an HWP document, “resume form.hwp.scr,” built on 27 February 2020. Execution replaces the initial SCR with a decoy HWP resume form whi…
VP of Counter Adversary Operations, CrowdStrike AI-Accelerated Threat Landscape: AI-Accelerated Threat Landscape: CrowdStrike's experts reveal how threat actors are evading traditional defenses by weaponizing AI, exploiting cross-domain blind spots, and t…
PwC’s 2019 retrospective includes several North Korea-linked developments within a broader threat landscape review. PwC tied the customized DTrack/Preft backdoor used in the Kudankulam Nuclear Power Plant incident to Black Artemis, its name for Lazarus, a…
ESRC identified a new Smoke Screen APT spear-phishing attack using a malicious Word document named as a letter from U.S. Deputy Secretary Biegun and assessed it as the same Kimsuky-linked activity seen in earlier lures. The document reuses a macro-enable …
Yoroi analyzed a Kimsuky-attributed infection chain that began with a Windows screensaver-style .scr loader and delivered a second-stage DLL disguised with a .tmp.db extension. The malware copied itself as AutoUpdate.dll under a Windows Defender-themed pa…
The 2020 UN Panel of Experts report says North Korea maintained and expanded nuclear and missile programs while evading sanctions through petroleum imports, maritime coal and sand exports, luxury goods procurement, and foreign trade networks. Its finance …
Two Chinese Nationals Charged with Laundering Over $100 Million in Cryptocurrency From Exchange Hack
The U.S. Justice Department charged Tian Yinyin and Li Jiadong with laundering more than $100 million in cryptocurrency tied to exchange hacks attributed in court filings to North Korean actors. The complaint says North Korean co-conspirators stole nearly…
ESRC observed a February 2020 APT attack using a screensaver executable named like a Korean HWP resume form to trick victims into launching malware. The activity is linked by ESRC with high confidence to Kimsuky and is described as a continuation of the O…
ESRC reports a Korean-language COVID-19 lure attributed as likely Kimsuky activity and analyzed as part of the group's SmokeScreen campaign. The spear-phishing targeted an international exchange and diplomacy-related organization with a malicious Word doc…
The Brambul follow-up analysis describes Lazarus-linked worm behavior associated with the pre-WannaCry malware family, focusing on the second routine that creates and runs lsasvc.exe. The malware adds a WindowsUpdate Run registry value for persistence, at…
The report reviews a set of US-CERT Malware Analysis Reports covering newly identified or updated North Korean implants attributed to Lazarus Group and HIDDEN COBRA. It summarizes tools such as SLICKSHOES and HOTCROISSANT as RAT or beacon-style implants u…