« Reports in 2020 »

204 reports

2020-03-04 • Igloo

Igloo summarizes Lazarus as a suspected North Korean state-backed group active against domestic Korean targets, with historical links cited to Operation Troy, Sony Pictures, Hidden Cobra, Andariel, and BlueNoroff. The analyzed cases center on malicious Ha…

#Lazarus
2020-03-04 • Tay

A malware analysis write-up describes a Kimsuky variant targeting South Korea with a resume-themed executable named like an HWP document, “resume form.hwp.scr,” built on 27 February 2020. Execution replaces the initial SCR with a decoy HWP resume form whi…

#Kimsuky
2020-03-03 • Crowd Strike

VP of Counter Adversary Operations, CrowdStrike AI-Accelerated Threat Landscape: AI-Accelerated Threat Landscape: CrowdStrike's experts reveal how threat actors are evading traditional defenses by weaponizing AI, exploiting cross-domain blind spots, and t…

#Trend #Chollima
2020-02-25 • Sentinel One

The report reviews a set of US-CERT Malware Analysis Reports covering newly identified or updated North Korean implants attributed to Lazarus Group and HIDDEN COBRA. It summarizes tools such as SLICKSHOES and HOTCROISSANT as RAT or beacon-style implants u…

#HiddenCobra #T1082 #T1090 #T1005 #T1041 #T1083 #T1027 #T1124 #T1204 #T1057 #T1003 #T1105 #T1055 #T1016 #T1048 #T1074 #T1056 #T1033 #T1012 #T1132 #T1043 #T1060 #T1064 #T1193 #T1065 #T1050 #T1024