AhnLab observed a malicious HWP lure titled “North Korea’s Gray-Zone Strategy and Countermeasures” that used an embedded EPS exploit for CVE-2017-8291. The EPS runs via gbb.exe, executes shellcode, and injects into HimTray.exe or HncCommTCP.exe, falling b…
« Reports in 2020 »
204 reports
The source compares a Kimsuky HWP malware case with the earlier “KINU Expert Advisory Request.hwp” activity and shows that the exploit and shellcode remain largely the same while keys, C2, filenames, and mutexes changed. Shellcode injected into HimTrayIco…
AhnLab analyzed a malicious Excel campaign whose court-judgment lure used macros to download and launch a second Excel document, then chained batch, VBS, and encoded CAB content from view-naver.com. The activity is described as sharing KONNI/Operation Mon…
ESRC reports that the Kimsuky/Thallium group continued using Windows Script File (.wsf) delivery in a Blue Estimate campaign with COVID-19-themed lure content. The script drops a decoy HWP document and a Base64-encoded patch.dll under ProgramData\Software…
AhnLab reports a maritime-themed malicious HWP that belongs to a broader set of recent HWP lure categories and changes its EPS pattern by leaving the EPS code unencoded, likely to vary detection. When the shellcode executes, it creates security.vbs under …
The available excerpt is an outline for a Korean TTP report about building an attack chain that uses spear phishing to collect information. It frames the activity across MITRE ATT&CK stages including initial access, execution, persistence, privilege escal…
Atlas Cybersecurity summarizes ClearSky reporting on CryptoCore, a cryptocurrency exchange theft group active since at least 2018. The group primarily targeted exchanges and related companies in the United States and Japan through reconnaissance and spear…
ThreatConnect identified an additional malware sample likely associated with Kimsuky, a DPRK-based group, because its behavior matched earlier AutoUpdate-linked activity. The sample shared a string deobfuscation routine and specific URL-parameter behavior…
ClearSky describes CryptoCore, also called Crypto-gang, Dangerous Password or Leery Turtle, as a persistent threat actor targeting cryptocurrency exchanges since at least 2018. The report says the group focused mainly on exchanges in the United States and…
AhnLab ASEC reported HWP malware distributed around South Korea’s academic conference season, including an online conference support-themed lure document. The document exploited the EPS vulnerability CVE-2017-8291 and used Windows utilities such as forfil…
ClearSky profiles CryptoCore, a financially motivated group targeting cryptocurrency exchanges and related supply-chain entities, mainly in the United States and Japan, since at least 2018. The group’s objective is access to exchange wallets and password …
IssueMakersLab reported that North Korea's Lazarus Group registered a malicious HWP document in a Korean Academy of Medical Sciences website notice. The lure was described as a notice about temporary permission for online academic conferences, and the pos…
ReversingLabs describes Hidden Cobra, often referred to as Lazarus, as a North Korea-linked APT and uses U.S. government reporting on COPPERHEDGE, TAINTEDSCRIBE, and PEBBLEDASH to show how defenders can expand IOC coverage. The article focuses on similari…
ESRC found multiple malicious files impersonating South Korea's Blue House security email and attributed them to Kimsuky's Blue Estimate campaign. The attack used a Windows Script File, bmail-security-check.wsf, containing Base64-encoded components that d…
ThreatConnect highlighted a suspected Kimsuky AutoUpdate malware sample connected to behavior described in ESTsecurity’s Operation Blue Estimate reporting. The source says the earlier file C315DE8AC15B51163A3BC075063A58AA was identified as a downloader, a…