Kimsuky Group Using Meterpreter to Attack Web Servers | ASEC has recently discovered the distribution of malware targeting web servers by Kimsuky group; a threat group deemed supported by North Korea. https://t.co/RV7ergaW93 @AhnLab_ASEC
#Trigona#Ransomware Attacking MS-SQL Servers.
Typical attacks that target MS-SQL servers include brute force attacks and dictionary attacks on systems where account credentials are poorly managed.
https://t.co/9D5khh6q5d
#Nevada#Ransomware is being distributed.
b673d92b77489d12779dc1fb5e8f6fdd
".NEVADA" extension
1. Main Features of Nevada Ransomware
2. Nevada Encryption Targets and Exception Conditions
https://t.co/akAMbasTv7
ASEC has recently discovered the #ShellBot, also known as #PerlBot, malware being installed on poorly managed Linux SSH servers.
If ShellBot is installed, Linux servers can be used as DDoS Bots for DDoS attacks against specific targets.
https://t.co/zaCcVrKpBS
ASEC discovered a malware strain disguised as a password file and being distributed alongside a normal file within a compressed file.
The recently discovered malware was in #CHM and #LNK file formats.
https://t.co/I6Yc5DF0yn
📝AhnLab Threat Intelligence Report
A comprehensive report on monitoring the activities of Kimsuky (FlowerPower, AppleSeed) in 2022
https://t.co/Q35K1uzbEe
https://t.co/9D0RnJ1XQ6
📝AhnLab Threat Intelligence Report
Unique characteristics of Kimsuky group’s spear phishing emails. Kimsuky used FQDN disguised as a famous Korean web portal.
https://t.co/bb28husMhl
https://t.co/o2MccWMYAc
#AhnLab#Kimsuky#Anlaysis#Thallium
#Mallox#ransomware, which targets vulnerable MS-SQL servers, has been historically distributed at a consistently high rate.
Mallox disguised as a program related to DirectPlay is a file built in .NET file.
📝Analysis:
https://t.co/WeBBCGsUWY
AhnLab Security Emergency response Center (ASEC) has recently discovered #CHM malware which is assumed to have been created by #Kimsuky.
It is distributed as an email attachment.
IOC:
726af41024d06df195784ae88f2849e4
C2:
hxxp://mpevalr.ria[.]monster
https://t.co/KjtzBBHgsC
❗MS-SQL Attack
The attacker used not only #CobaltStrike but also #Netcat to gain control over the infected system.
It targets poorly managed MS-SQL servers.
Various other malware were also installed like privilege escalator, infostealer, and proxy tools.
https://t.co/fVtMOz7iLu
According to ASEC the North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year. https://t.co/MNRy8rPSmx @TheHackersNews
#iswr#ransomware can be decrypted!!!
iswr ransomware is a variant of #STOP ransomware.
#AhnLab#ASEC offers a free script for decrypting files infected by iswr ransomware.
😆https://t.co/zXNhQMDTST
ASEC has recently discovered the installation of the #PlugX#malware through the Chinese remote control programs #Sunlogin and #Awesun’s remote code execution #vulnerability
https://t.co/UJBbM1bQpm
#Lazarus exploited a zero-day #vulnerability in Korea’s widely used digital signature authentication software. They attacked Korean defense contractors, satellite companies, IT, and media companies. #0day
This report will be translated into English soon.
https://t.co/lsXnxdN6Oj
Anti-Forensic Techniques Used By #Lazarus Group
- Data Hiding: Encryption, Other Forms of Data Hiding
- Artifact Wiping: File Wiping
- Trail Obfuscation: Timestamp Changes
📝Analysis by #AhnLab#ASEC#AFIRST
https://t.co/XhhRoC9BpE
#Magniber#Ransomware’s Relaunch Technique using Windows Registry 🤐
Registering to be relaunched is a preliminary phase of encryption.
https://t.co/r6z7AOtm9T