« Reports in 2026

553 reports

2026-08-01 • NKInternet

A newly surfaced version of North Korea’s SiliVaccine antivirus replaces the stolen Trend Micro engine found in 2018 with ClamAV signatures and Malheur-based behavioral clustering. Internal artifacts still point to suspected developer PGI, while the user-…

#OpSec
2026-07-30 • Plainbit

PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shel…

#Wateringhole #Fileless
2026-07-30 • S2W

S2W analyzed three malware clusters targeting South Korea that combine legitimate-process abuse, DLL side-loading, encrypted payload staging, and manual PE mapping. Two chains deploy SIGNBT v0.0.1 or v1.2 from service-registry blobs or embedded containers…

#Fileless #SIGNBT #T1027.013 #T1082 #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1083 #T1036.005 #T1105 #T1620 #T1573.001 #T1049 #T1016 #T1070.006 #T1027.007 #T1574.001 #T1055.001 #T1033 #T1569.002 #T1012