The Korean malware analysis links a Lunar New Year-themed sample to activity resembling an earlier Vietnamese event estimate lure associated with Kimsuky reporting. The executable contains a PDF decoy instead of an HWP document, drops and runs a malicious…
« Reports in 2020 »
204 reports
Chainalysis analyzed Lazarus Group cryptocurrency theft and laundering behavior in 2019, noting greater use of mixers and CoinJoin wallets to obscure stolen funds. The report describes the DragonEx intrusion as an unusually elaborate phishing operation in…
Chainalysis’ Crypto Crime Report excerpt says 2019 saw more cryptocurrency exchange attacks than any prior year, but total confirmed exchange-theft losses fell to about $283 million because no single incident matched earlier mega-heists. The source explai…
ESTsecurity observed Konni APT spear-phishing documents disguised as North Korea Central Committee plenary meeting material and Tokyo Paralympics-related content. The malicious documents used social or geopolitical lures, Korean code page characteristics,…
ThreatBook reported a cluster it named DangerousPassword after finding compressed trojan packages built around cryptocurrency-themed lures such as monthly business reports, job descriptions, project risk briefs, and salary guidance. The activity targeted …
Kaspersky reported continued Lazarus Group operations against cryptocurrency businesses after Operation AppleJeus. The actor used fake companies and manipulated applications to gain trust, then delivered macOS and Windows malware through multi-stage infec…
The report tracks Konni malware campaigns that used malicious macro-enabled Word documents with Korean Peninsula and DPRK foreign-affairs themes. One observed lure targeted Russian-language speakers interested in dialogue between the United States and Nor…
Objective-See’s Mac malware year-in-review covered several macOS threats from 2019, including Lazarus-linked activity against cryptocurrency businesses. The source notes Lazarus group backdoors and CookieMiner-style activity that used launch agents for pe…