Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Asec: RedEyes (ScarCruft)’s CHM Malware Using the Topic of Fukushima Wastewater Release https://asec.ahnlab.com/en/56857/ #MalwareInformation #ScarCruft #backdoor #RedEyes #APT37 #chm
#malwareinformation #scarcruft #backdoor #redeyes #apt37 #chm
Die vom nordkoreanischen Staat gesponserte Hackergruppe #ScarCruft (#APT37) hat die IT-Infrastruktur und den E-Mail-Server von NPO Mashinostroyeniya gehackt.
NPO Mashinostroyeniya ist ein russischer Konstrukteur und Hersteller von Orbitalfahrzeugen, Raumfahrzeugen und taktischen Verteidigungs- und Angriffsraketen, die von der russischen und indischen Armee eingesetzt werden.
#scarcruft #apt37 #hack #russland #nordkorea #opencarrot #windows
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Hackmageddon: 16-30 June 2023 Cyber Attacks Timeline https://www.hackmageddon.com/2023/08/01/16-30-june-2023-cyber-attacks-timeline/ #CyberAttacksTimelines #PBIResearchServices #AnonymousSudan #CVE-2023-34362 #CyberEspionage #NoName057(16) #CyberAttacks #CyberWarfare #LazarusGroup #MustangPanda #CyberCrime #Hacktivism #Ransomware #Security #JokerSpy #Timeline #REF9134 #MOVEit #APT15 #APT28 #APT29 #APT37 #2023 #Cl0p #Clop #June
#cyberattackstimelines #pbiresearchservices #anonymoussudan #cve #cyberespionage #noname057 #cyberattacks #cyberwarfare #lazarusgroup #mustangpanda #cybercrime #hacktivism #ransomware #security #jokerspy #timeline #ref9134 #moveit #apt15 #apt28 #apt29 #apt37 #cl0p #clop #june
Happy Tuesday everyone! #APT37 is the topic of today's #readoftheday, specifically ThreatMon takes a deep-dive into the #RokRat malware, which is a remote access trojan (RAT). Enjoy and Happy Hunting!
Link to article in the comments!
***AS usual I am going to leave one of the MITRE ATT&CK blank. I would like to see if any of you that see this can help FILL in that blank! If so, leave your thoughts in the comments OR send me a DM!***
Notable MITRE ATT&CK TTPs:
TA0007 - Discovery
T1087 - Account Discovery
T1083 - File and Directory Discovery
T1018 - Remote System Discovery
T1082 - System Information Discovery
TA0009 - Collection
T[What technique covers the threat actor capturing information under the TEMP folder?] - Good luck!
TA0011 - Command And Control
T1071.001 - Application Layer Protocol: Web Protocols
TA0002 - Execution
T1059.003 - Command and Scripting Interpreter: Windows Command Shell
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting
#apt37 #readoftheday #RokRat #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting
Any #cybersecurity peeps on here have any info on the #APT37 POORAIM backdoor? It was mentioned in an @Trellix (Fireeye) report, but i can find any details.. very little about it from my searching over the last week. I've a MSc Cybersecurity assignment to analyse it 🥹
he victimology of this event fits very closely with the modus operandi of groups such as #APT37 and #Kimsuky. More analysis from the industry greatly appreciated. #threatintelligence
https://thehackernews.com/2023/02/experts-warn-of-rambleon-android.html
#apt37 #kimsuky #threatintelligence
APT - Lazarus Group overview
#Lazarus #APT / #HIDDENCOBRA / #ZINC / #APT37 / #Andariel / #BlueNoroff
#cyberattack #phishing #databreach #cybercrime #cyberespionage
https://tribalsec.substack.com/p/cyberthreat-apt-lazarus-group-overview
#lazarus #apt #hiddencobra #zinc #apt37 #andariel #bluenoroff #cyberattack #phishing #databreach #cybercrime #cyberespionage