NCC Group RIFT analyzed Lazarus-linked macro documents that execute shellcode without the more commonly detected WriteProcessMemory or CreateThread APIs. The macros trigger through a Microsoft Forms ActiveX control, allocate an executable heap, decode she…
« Reports in 2021 »
218 reports
JPCERT documented commonly available tools observed in Lazarus intrusions, emphasizing that the group supplements malware with legitimate utilities after gaining access. For lateral movement and network discovery, the excerpt names AdFind for Active Direc…
ESRC reported a Thallium/Kimsuky-attributed campaign using a malicious DOC disguised as a survey about the incoming Biden administration and U.S. foreign and security policy. The document displayed a fake Office update prompt to induce macro enablement; o…
The JSAC presentation analyzes Operation Bitter Biscuit, a targeted attack campaign reported by multiple security vendors against government, military, defense, and some IT targets. The observed intrusion began with a compressed file attached to a targete…
NTT Security’s VB2020 presentation analyzed CryptoMimic, also known as Dangerous Password, an APT actor observed since around March 2018 targeting companies worldwide with emphasis on cryptocurrency organizations. The source describes initial LNK and macr…
K7 Labs' Ghost Mach-O talk analyzes Lazarus macOS malware used in cryptocurrency exchange targeting. The transcript describes AppleJeus style spear phishing in which a victim is directed to a fake trading application site, downloads a signed package, and …
Malwarebytes analyzed a malicious Office document, likely aimed at South Korean government-related targets, that it associates with APT37/ScarCruft based on the injected RokRat payload. The macro used a VBA self-decoding technique to unpack and execute ma…
ESRC reported that the North Korea-linked Thallium group modified a private stock-investment messenger installer to conduct a software supply-chain attack, expanding beyond its usual spear-phishing activity. The NSIS installer executed wmic.exe to retriev…