AttackIQ summarizes Lazarus Group Operation In(ter)ception as a 2019 campaign that used LinkedIn and email job lures from fake HR representatives at companies such as Collins Aerospace and General Dynamics. Victims received password-protected RAR archives…
« Reports in 2024 »
657 reports
The podcast describes ScarCruft as a North Korean state-backed hacking unit focused on espionage against journalists, dissidents, cybersecurity experts, and organizations that report on North Korea. Daily NK, a Seoul-based outlet with defectors on staff a…
Andariel activity is reported to involve abuse of MeshAgent as command-and-control tooling against South Korean companies. The source says the operators downloaded a MeshAgent C2 component named fav.ico from an external source and used lateral-movement ac…
Reaper, also tracked as APT37, InkySquid, RedEyes, ScarCruft, and Group123, is described as using a malicious HWP-themed lure related to South Korea's twentieth presidential election and election-observer recruitment. The report frames the actor as a Nort…
Vedalia, also known as Konni, is described as using oversized LNK files in a malware campaign intended to hide the real shortcut extension and frustrate casual analysis. The report notes double extensions, excessive whitespace, and shortcut content design…
Plainbit analyzed a paymentconfirmation.chm sample that used a normal-looking help window to hide script execution through hh.exe, cscript, VBS, batch files, and PowerShell. The CHM unpacked files under C:\Users\Public\Libraries, registered emlmanager.vbs…
WIRED profiles Alejandro Caceres, also known as P4x, who says he disrupted North Korea’s public internet infrastructure in 2022 after North Korean operators targeted him and other U.S. security researchers. The article describes his use of custom programs…
While strategic spear-phishing campaigns targeting researchers who study the Korean Peninsula remained a constant trend, North Korean threat actors appeared to make greater use of legitimate software to compromise even more victims. Since our last report …
Moreover, the RAT’s command-and-control (C2) infrastructure serves as a conduit for hosting newer variants of known Lazarus implants, such as TigerRAT. In September 2022, cybersecurity researchers at Cisco Talos made a significant discovery: a new Remote …
Hauri reports a spear-phishing operation assessed as likely Kimsuky activity in which an attacker impersonated the South Korean Embassy in China to target a Seoul National University professor. The operator conducted natural back-and-forth email communica…
A North Korean npm supply chain campaign used Python post-infection scripts against developers instead of relying only on malicious DLL delivery. The malicious Frontend.zip package retrieved an obfuscated main script that created a .n2 directory, then dow…
NSHC's January 2024 ThreatRecon report lists SectorA as the most active DPRK-relevant group family in a broad monthly roundup of 26 hacking groups. SectorA01 used malware disguised as PuTTY against targets in countries including Spain, the United States, …
Plainbit analyzes a North Korea-linked RokRAT infection chain delivered in a ZIP archive containing a same-named LNK file disguised as an HWP document. The shortcut runs cmd.exe and PowerShell, hides the command window with user32.dll calls, splits embedd…
A Kimsuky-attributed RAR archive used a Korean Embassy in China policy-meeting theme to lure likely embassy or policy-related personnel into running a shortcut file disguised with an HWP-style document icon. The LNK launches hidden PowerShell, extracts em…
Cointelegraph reports that Solana-based Telegram trading bot Solareum shut down after a security breach, funding problems, and changing market conditions. The exploit enabled wallet drainers to steal more than 2,800 SOL, worth about $520,000, from more th…