VP of Counter Adversary Operations, CrowdStrike CTO of Americas, CrowdStrike AI-Accelerated Threat Landscape: Year of the Evasive Adversary Virtual Threat Briefing CrowdStrike's experts reveal how threat actors are evading traditional defenses by weaponiz…
« Reports in 2021 »
218 reports
U.S. charges against three North Korean men covered a financially motivated Lazarus theft campaign that stole about $1.3 billion from banks and cryptocurrency exchanges, including the Bangladesh Bank heist. Symantec links the activity to Banswift malware …
CISA, the FBI, and the U.S. Treasury attribute Ants2Whale to North Korea’s Lazarus Group and describe it as an AppleJeus variant used in cryptocurrency-targeting operations. The macOS installer presents a functional cryptocurrency application while deploy…
North Korean state-sponsored Lazarus Group actors distributed Dorusio, a Windows and macOS AppleJeus cryptocurrency wallet containing malicious upgrade components. The updaters established persistence, collected basic host information, and contacted `doru…
The FBI, CISA, and U.S. Treasury attribute CoinGoTrade, an AppleJeus cryptocurrency application, to North Korean state-sponsored Lazarus Group activity. Its Windows and macOS installers delivered legitimate-looking trading software alongside persistent up…
CISA, the FBI, and the U.S. Treasury attributed the Kupay Wallet AppleJeus operation to North Korea's Lazarus Group, which used a legitimate-looking cryptocurrency wallet to target individuals and financial-sector organizations. Windows and macOS installe…
CISA, the FBI, and the U.S. Treasury attribute the Union Crypto version of AppleJeus to North Korean state-sponsored Lazarus Group actors targeting cryptocurrency users and companies. The operation distributed legitimate-looking Windows and macOS trading …
CISA, the FBI, and the U.S. Treasury attribute the JMT Trading version of AppleJeus to North Korean state-sponsored Lazarus Group activity targeting cryptocurrency users and businesses. Malicious Windows and macOS installers paired a functioning trading c…
CISA, the FBI, and the U.S. Treasury attribute the Trojanized Celas Trade Pro cryptocurrency application to North Korean state-sponsored Lazarus Group activity. Windows and macOS installers presented a functional clone of QT Bitcoin Trader while adding an…
ESTsecurity analyzed a Thallium-attributed malicious HWP document disguised as a COVID-19 small-business support guide. The document used embedded OLE objects and fake confirmation imagery to lure the user into launching apisecurity.vbs, which staged apis…
FBI, CISA, and Treasury assessed that North Korean state-sponsored Lazarus Group/HIDDEN COBRA actors used AppleJeus malware to target cryptocurrency exchanges, financial services firms, and related organizations for theft. The advisory says the operators …
The U.S. Justice Department indictment alleged that three North Korean RGB-linked programmers, associated in security reporting with Lazarus Group and APT38, conducted a long-running conspiracy spanning destructive attacks, financial theft, extortion, and…
presentation/GReATIDEA2021_Lazarus.pdf at main · theseongsu/presentation · GitHub You signed in with another tab or window. You must be signed in to change notification settings Files Expand file tree / GReATIDEA2021_Lazarus.pdf File metadata and controls…
Chainalysis attributed the 2020 KuCoin exchange hack, involving roughly $275 million in stolen cryptocurrency, to Lazarus Group based partly on laundering patterns previously associated with the North Korean actor. The report says the attackers gained acc…
ASEC observed malware distributed as a PIF executable disguised as a revised 2021 Ministry of National Defense work-report document. When run, the file displayed a legitimate PDF copied from the ministry website while silently dropping a malicious DLL at …