« Reports in 2025 »

792 reports

2025-08-19 • Woo X

WOO X attributed a July 24, 2025 cryptocurrency-theft incident to suspected North Korea-linked activity, citing evidence for UNC4899 and later considering UNC4899 or UNC5565 involvement. The intrusion began when a developer accepted an open-source collabo…

#UNC4899 #WooX
2025-08-18 • Trellix

Trellix attributes an active early-2025 espionage campaign against embassies and foreign ministries in Seoul to DPRK-linked actors, with infrastructure overlaps to known Kimsuky operations. The attackers sent at least 19 spear-phishing emails impersonatin…

#Kimsuky #Phishing #LNK #XenoRAT #T1102.002 #T1082 #T1567.002 #T1071.001 #T1112 #T1083 #T1027 #T1204.002 #T1566.002 #T1059.005 #T1566.001 #T1053.005 #T1059.001 #T1036.005 #T1105 #T1087.001 #T1106 #T1134 #T1071.004 #T1568 #T1102.003 #T1569 #T1033 #T1569.002
2025-08-14 • Ghost Wolf Lab

A leaked Kimsuky data set is described as exposing internal files and tools tied to backdoors, phishing frameworks, and reconnaissance activity after a compromise around early June 2025. The excerpted work.zip analysis highlights operator tooling rather t…

#Kimsuky #APTDown
2025-08-13 • Bloo

DRATzarus, also tracked as ThreatNeedle, is described as a Lazarus Group remote access trojan used since at least mid-2020 against defense and aerospace organizations. The excerpt says delivery commonly relies on targeted spear-phishing with COVID-19 or f…

#DRATzarus #Lazarus #T1059.003 #T1140 #T1005 #T1041 #T1113 #T1071.001 #T1083 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1547.001 #T1105 #T1027.002 #T1548.002 #T1036.003 #T1010 #T1021.002 #T1569.002 #T1543.003