« Reports in 2020 »

204 reports

2020-07-03 • kino

The source compares a Kimsuky HWP malware case with the earlier “KINU Expert Advisory Request.hwp” activity and shows that the exploit and shellcode remain largely the same while keys, C2, filenames, and mutexes changed. Shellcode injected into HimTrayIco…

#Kimsuky
2020-06-24 • Clearskysec

ClearSky describes CryptoCore, also called Crypto-gang, Dangerous Password or Leery Turtle, as a persistent threat actor targeting cryptocurrency exchanges since at least 2018. The report says the group focused mainly on exchanges in the United States and…

#Cryptocurrency #CryptoCore
2020-06-19 • Threatconnect

ThreatConnect highlighted a suspected Kimsuky AutoUpdate malware sample connected to behavior described in ESTsecurity’s Operation Blue Estimate reporting. The source says the earlier file C315DE8AC15B51163A3BC075063A58AA was identified as a downloader, a…

#Kimsuky #AutoUpdate