The source analyzes Brambul, a Lazarus-linked worm that predates WannaCry and shares interest in SMB-based propagation. It describes how the malware generates IP addresses, attempts connections to TCP port 445, and uses IPC and service-control activity wh…
« Reports in 2020 »
204 reports
Objective-See examined how a Lazarus AppleJeus macOS loader could be repurposed for red-team or offensive use. The source explains that the Lazarus malware’s first-stage loader beacons to a remote server and can execute second-stage payloads directly from…
PwC describes Black Banshee, also known as Kimsuky, as a North Korea-based espionage actor that ran multiple 2019 campaigns spanning broad credential harvesting, spear-phishing, targeted espionage, and data exfiltration. The report focuses on infrastructu…
CISA, FBI, and DoD analyzed BUFFETLINE, a Trojan malware variant attributed to North Korean government activity tracked as HIDDEN COBRA. The report describes a full-featured beaconing implant that uses PolarSSL for session authentication and a FakeTLS sch…
CISA, FBI, and DoD identify BISTROMATH as a North Korean government-linked HIDDEN COBRA Trojan family with multiple RAT implant versions and CAgent11 GUI controller and builder components. The implants can survey systems, upload and download files, execut…
CISA, FBI, and DoD identify SLICKSHOES as a North Korean government-linked HIDDEN COBRA Trojan built as a Themida-packed dropper and beaconing implant. The dropper decodes and writes taskenc.exe under C:\Windows\Web but does not execute it or create persi…
CISA, FBI, and DoD analyzed CROWDEDFLOUNDER, a North Korean government-linked Trojan associated with HIDDEN COBRA activity. The malware is a Themida-packed 32-bit Windows executable designed to unpack and execute a remote-access Trojan. Its command-line h…
CISA, FBI, and DoD analyzed HOTCROISSANT as a full-featured beaconing implant identified with North Korean government activity tracked as HIDDEN COBRA. The sample attempts to connect to a hardcoded C2 IP, immediately sends victim information, and then wai…
CISA, FBI, and DoD analyzed ARTFULPIE as a North Korean government-linked Trojan variant associated with HIDDEN COBRA activity. The implant functions as a downloader and in-memory loader, retrieving a DLL from a hardcoded URL and manually loading it into …
CISA, FBI, and DoD analyzed HOPLIGHT, a North Korean government-linked malware set associated with HIDDEN COBRA. The report covers twenty malicious executables, including proxy applications that mask traffic between infected hosts and remote operators. Se…
Recorded Future's Insikt Group analyzed 2019 internet activity by North Korean senior leadership using third-party data, IP geolocation, BGP routing, network traffic, and OSINT. The report assesses that the internet had become critical for DPRK revenue ge…
The source provides a narrative history of Lazarus Group operations, including the Bangladesh Bank SWIFT theft attempt and WannaCry ransomware activity. It describes the Bangladesh Bank case as a phishing-enabled intrusion that reached systems used for SW…
ESTsecurity reported a February 2020 Operation Blue Estimate variant that masqueraded as a scanned resident-registration PDF tied to a former education-sector official. The malware used a double-extension SCR executable, displayed a decoy image, and dropp…
Seongsu Park’s K-CTI 2020 Lazarus slides emphasize that threat intelligence is broader than IOC lists alone. The extracted slide text shows a loader and C2 chain involving update.exe, a .NET loader, injection into iexplorer.exe, a tainted loader, and encr…
Unit 42 described a campaign using malicious documents with North Korea-themed Russian-language lures to target a U.S. government agency and foreign nationals associated with North Korea. The malware set included CARROTBAT downloaders, a newer CARROTBALL …