ESRC analyzed a spear-phishing attack against a South Korean securities-company employee and attributed the operation to Lazarus. The email carried many HWP, XLSX, JPEG, and large attachments as decoys, with the first HWP file containing malicious PostScr…
« Reports in 2020 »
204 reports
McAfee ATR's Speakerdeck abstract frames Hidden Cobra, also known as Lazarus, as a North Korea-linked actor active since at least 2007. The talk focuses on 2018 research into campaigns using complex implants for intelligence collection, operational disrup…
ASEC reports malicious HWP documents distributed by email under real-estate investment themes, with plausible message and document content used to lure Korean-speaking recipients into opening attachments. The malicious HWP contains an EPS object that expl…
IssueMakersLab reported observations from North Korean attacks on the defense contractor sector. The post separates targeting by RGB unit, saying RGB-D3 mainly focused on aerospace and defense companies while RGB-D5 mainly targeted artillery ammunition an…
PebbleDash is described as a North Korea-linked Hidden Cobra/APT38/Lazarus remote access tool whose FakeTLS mechanism hides command-and-control traffic inside traffic that resembles a normal TLS handshake. The analyzed sample used dynamic library loading …
Alyac reports continued Lazarus activity against overseas defense companies, including new malicious Word documents named LM_IFG_536R.docx, BAE_JD_2020.docx, and Boeing_AERO_GS.docx. The documents use an external template relationship to retrieve attacker…
MalwareLab analyzed a Lazarus-attributed validator from malicious Word documents impersonating Lockheed Martin and linked the samples to a broader campaign probably aimed at military contractors doing business with South Korea. The documents embedded two …
CISA and the FBI identified ten publicly known vulnerabilities most frequently exploited by state, nonstate, and unattributed actors during 2016–2019, with Microsoft OLE flaws dominating the list. CVE-2017-11882, CVE-2017-0199, and CVE-2012-0158 were wide…
CISA, the FBI, and the Department of Defense identified PEBBLEDASH as a full-featured Trojan used by the North Korean government under the HIDDEN COBRA designation. The Windows implant provides file transfer and execution, command-line access, process con…
CISA attributes TAINTEDSCRIBE to the North Korean government activity it tracks as HIDDEN COBRA. The Windows implant masquerades as Microsoft Narrator, persists through the user's Startup folder, and connects to 211.192.239.232 over TCP port 8443 using a …
DHS, FBI, and DoD identified COPPERHEDGE as Manuscrypt-family remote-access malware used by the North Korean government and tracked under HIDDEN COBRA. The malware can execute arbitrary commands, perform system reconnaissance, exfiltrate data, and use pro…
CISA, the FBI, and the Department of Defense reported three malware variants used by the North Korean government, which the U.S. Government tracks as HIDDEN COBRA activity. U.S. Cyber Command released samples for the variants to VirusTotal so defenders co…
The excerpt describes a Lazarus campaign using a COVID-themed HWP document targeting South Korea, including a Jeollanam-do coronavirus inquiry lure. OSINT analysis found the executable was downloaded from sofa.rs and matched detection logic for a reflecti…
AhnLab observed increased Lazarus activity against defense-related targets using Office Open XML Word documents themed around BAE Systems, Boeing, and U.S.-ROK diplomatic security. The documents reached external template URLs to download macro-enabled .do…
Alyac reports a Geumseong121 APT scenario built around long-running social engineering against South Korean figures connected to unification and North Korea policy. Operators first impersonated a newly appointed female senior researcher in the unification…