« Reports in 2021 »

218 reports

2021-01-28 • kkoha

This Korean analysis describes DPRK-linked malware activity targeting security researchers through fake vulnerability research collaboration and an actor-controlled blog at blog.br0vvnn[.]io. The attack chain used malicious exploit PoC projects whose buil…

#DreamJob
2021-01-28 • Microsoft

Microsoft attributed a campaign targeting security researchers to ZINC, a DPRK-affiliated state-sponsored group, after detecting attacks against penetration testers, private offensive researchers, and employees at security and technology companies. The op…

#DreamJob #Zinc
2021-01-26 • JPCERT

JPCERT/CC’s English Operation Dream Job report analyzes Torisma and LCPDot malware used by Lazarus/Hidden Cobra. Torisma is a rundll32-executed downloader that loads C2 configuration from a signed local file, uses the VEST-32 algorithm and a repeated encr…

#DreamJob #Lazarus
2021-01-26 • Cisco Talos

Cisco Talos reported that multiple Talos researchers received messages linked to the same security-researcher targeting campaign described by Google TAG. One researcher was contacted on January 11 with the same lure seen in public reporting, and the attac…

#DreamJob
2021-01-25 • Google

The actors behind this campaign, which we attribute to a government-backed entity based in North Korea, have employed a number of means to target researchers which we will outline below. To date, we have only seen these actors targeting Windows systems as…

#DreamJob