The report describes malicious Word documents themed around North Korean COVID-19 conditions that used VBA macros to drop a secondary payload and connect infected systems to attacker command-and-control infrastructure. The payload was identified as Amadey…
« Reports in 2021 »
218 reports
ThreatBook analyzed a Konni APT campaign using a North Korea COVID-19 supplies article as a lure document, consistent with the group’s long-running spear-phishing against South Korea and regional targets. The malicious Word document hid its text until mac…
Norfolk Infosec analyzed a malicious helpsvc.sys component from a DPRK-affiliated campaign targeting security researchers, likely delivered through a watering-hole route rather than the earlier Visual Studio social-engineering chain. The file behaves like…
NTT Security Japan reported changes in CryptoMimic activity, a financially motivated targeted attack group also known as Dangerous Password, CageyChameleon, Leery Turtle, or CryptoCore and described as having possible Lazarus links. The group continued ta…
This Korean analysis describes DPRK-linked malware activity targeting security researchers through fake vulnerability research collaboration and an actor-controlled blog at blog.br0vvnn[.]io. The attack chain used malicious exploit PoC projects whose buil…
The archived analysis reverse-engineers Torisma and LCPDot malware used in Lazarus/Hidden Cobra Operation Dream Job activity. Torisma is described as collecting host and process information, creating malicious pipes, loading DLLs, encrypting C2 communicat…
Microsoft attributed a campaign targeting security researchers to ZINC, a DPRK-affiliated state-sponsored group, after detecting attacks against penetration testers, private offensive researchers, and employees at security and technology companies. The op…
The JSAC presentation explains hunting methods for threat intelligence related to cryptocurrency-business targeting campaigns, including activity affecting Japanese cryptocurrency operators. It references campaigns publicly reported by JPCERT/CC, ClearSky…
Malware mentioned in “North Korean hackers have targeted security researchers via social media report” published by Google Threat Analysis Group (TAG) is considered to be a ThreatNeedle which is dubbed by Kaspersky. In addition, the malware and C2 communi…
JPCERT/CC’s English Operation Dream Job report analyzes Torisma and LCPDot malware used by Lazarus/Hidden Cobra. Torisma is a rundll32-executed downloader that loads C2 configuration from a signed local file, uses the VEST-32 algorithm and a repeated encr…
JPCERT/CC describes two Lazarus/Hidden Cobra malware families, Torisma and LCPDot, used during intrusion and post-intrusion operations. Torisma is a rundll32-launched downloader that reads configuration files, uses a fixed signature and VEST-32 encryption…
360 attributed “Operation Breaking the Shell” to Lazarus/APT-C-26 and described it as a long-prepared campaign against security researchers. The operators built credibility by registering social-media personas, running the blog blog.br0vvnn[.]io, publishi…
Cisco Talos reported that multiple Talos researchers received messages linked to the same security-researcher targeting campaign described by Google TAG. One researcher was contacted on January 11 with the same lure seen in public reporting, and the attac…
The actors behind this campaign, which we attribute to a government-backed entity based in North Korea, have employed a number of means to target researchers which we will outline below. To date, we have only seen these actors targeting Windows systems as…
ESTsecurity ESRC reported a Thallium spear-phishing campaign timed around Korean year-end tax settlement activity and disguised as a 2021 COVID-19 donation-certificate request. The lure email delivered a ZIP containing a benign-looking PDF and an Excel bi…