The FASTCash paper explains how a DPRK-nexus group abused ISO 8583 payment-switch messaging to force approval of fraudulent ATM withdrawals. FASTCash malware is injected into a bank payment switch process and hooks send and recv so attacker-controlled car…
« Reports in 2020 »
204 reports
McAfee ATR observed a 2020 Operation North Star activity set using malicious job-offer documents to target aerospace and defense interests and install data-gathering implants. The activity used legitimate defense-contractor job postings as lures, template…
McAfee’s defensive guidance ties Operation North Star to targeted malicious job-posting documents against aerospace and defense interests during 2020. The excerpt says the campaign used spear-phishing attachments or vulnerability exploitation for initial …
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence showed a MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. One European incident used a victim-specific spreadin…
SentinelOne describes four macOS malware families likely tied to the same North Korean-backed Lazarus operators behind AppleJeus activity. The excerpt highlights DaclsRAT in a trojanized TinkaOTP one-time-password app, which used LaunchAgents or LaunchDae…
ESRC assesses that a year-long sequence of Korean spear-phishing activity is likely directly or indirectly connected to the Thallium group, which Microsoft had linked to targeting government, think-tank, university, human-rights, and related victims. The …
ASEC reporting describes a malicious HWP document containing EPS/PostScript content that executes shellcode and CMD commands. The lure appears to abuse a legitimate origin self-check form from a government legal-information source, while related activity …
Reporting on Dacls describes a remote access trojan attributed by researchers to the Lazarus Group, also known as Hidden Cobra. The malware can affect Windows and Linux systems and is discussed in the context of data theft and ransomware-enabled intrusion…
AhnLab ASEC found malware distributed through a Korean community download board as a trojanized utility rather than a document lure. The attacker modified a legitimate utility executable by adding an executable .ireloc section with shellcode and changing …
Kaspersky describes MATA as a multi-platform malware framework used since at least April 2018 to infiltrate corporate environments across Windows, Linux, and macOS systems. The Windows toolchain includes a loader that decrypts a next-stage payload, an orc…
Bitquery traces the November 2019 Upbit breach in which 342,000 ETH, then valued at about $48.1 million, was moved from the Korean exchange to attacker-controlled wallets. The laundering pattern used multiple intermediate wallets and layered transactions …
ESET found malicious macOS cryptocurrency trading applications that copied or rebranded the legitimate Kattana app under names such as Licatrade and Cointrazer, continuing GMERA-style activity previously reported by Trend Micro. The trojanized bundles tar…
AhnLab observed COVID-19 prediction-themed phishing distributing malicious Excel documents that entice users to enable macros with a “Predict” calculation button. The macro contains obfuscated downloader commands that use curl and certutil -decode to fetc…
AhnLab analyzed a malicious HWP document impersonating a cryptocurrency company policy update and using a linked object/OLE executable named hanwordupdate.exe to trick users into launching it. The embedded EXE contains a Base64-encoded PowerShell script t…
Sansec attributed a set of Magecart-style digital skimming operations against US and European online stores to HIDDEN COBRA based on reused infrastructure and distinctive malware code patterns tied to prior North Korean activity. The actor gained unauthor…