π AhnLab TIP Weekly Report β 1st week of Juneπ
π Qilin listed a South Korean industrial automation equipment company as a new victim
π₯ Black X posted internal data from a South Korean plastic surgery clinic on its leak site
π Nova listed the AI department of a university in Daegu, South Korea, as a new victim
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 4th week of Mayπ
π« Customer data from a Japanese education franchise is being sold on a cybercrime forum
π Data from a Japanese government agency handling national civil-service HR is being sold on a cybercrime forum
β½οΈ The FBI warned of phishing attacks spoofing official FIFA websites
#Cybersecurity #Ransomware #TI
A recent case involving malicious files disguised as security emails from a major Korean credit card company has been confirmed.
The attack flow is similar to a previous Kimsuky LNK malware distribution case.
Read the ASEC blog for the full analysis.
πhttps://t.co/sizthnH6dl
π AhnLab TIP Weekly Report β 3rd week of Mayπ
π Nova named a South Korean cosmetics and chemical firm as a new victim
οΏ½οΏ½οΏ½ CoinbaseCartel claims a data leak from an open-source visualization platform
π¨π»βπ» TeamPCP claims to be selling source code leaked from a major developer platform
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 2nd week of Mayπ
π₯ CoinbaseCartel listed a South Korean medical ultrasound maker as a new victim
πΎ Leak Bazaar's DLS, active since March, was identified
π¨π»βπ» TeamPCP and BreachForums announced a supply chain attack contest
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 1st week of Mayπ
ποΈ Data from Guatemalan government agencies is being sold on a cybercrime forum
π BlackWater listed a Chinese auto parts manufacturer as a new ransomware victim
π³ A Japanese fintech firm disclosed unauthorized access after GitHub credentials were exposed
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 5th week of Aprilπ
π Β New ransomware group M3RX emerged
βͺ Data from a South Korean religious organization is being sold on a cybercrime forum
π¬ ShinyHunters claimed it stole data from a U.S. interactive media company
#Cybersecurity#Ransomware #TI
π AhnLab TIP Weekly Report β 4th week of Aprilπ
πͺ ShinyHunters claimed to have leaked data related to a U.S. convenience store chain
π» ShinyHunters claimed to have leaked data and source code from a U.S. software firm
π The infrastructure of the new data extortion group Prinz Eugen was identified
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 3rd week of Aprilπ
π New ransomware TiMC, BlackWater, and Lamashtu identified
π§ NoName05716 claimed DDoS attacks on South Korea over support for Ukraine
π¦ A joint campaign by VECT ransomware and TeamPCP is spreading
#Cybersecurity#Ransomware #TI
π¨Cyber threat actors are consistently attempting to exploit living off the land binaries built into systems to bypass detection by security products.
Check the ASEC blog to discover the techniques, real world attack cases and counter measures.
https://t.co/rXcU9oVVug
π AhnLab TIP Weekly Report β 2nd week of Aprilπ
π KryBitβs leak and mirror sites were observed
π Gunra listed a South Korean pharmaceutical company as a new victim
π§ͺ DragonForce listed an Egyptian generic drug developer and manufacturer as a new victim
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 1st week of Aprilπ
π NetRunner claimed to have stolen about 960GB of data from the Indian branch of a South Korean auto parts manufacturer
π Everest claimed theft of about 910GB of data from a Japanese automaker
π§ ShinyHunters claimed a breach of a US network company,
#Cybersecurity #Ransomware #TI
β οΈASEC recently identified a change in the #Kimsuky groupβs method of distributing malicious LNK files. Overall attack flow remains the same but structural change was observed in the intermediate execution phase.
Check the full analysis on the ASEC Blog: https://t.co/AFZQ6zcv88
π AhnLab TIP Weekly Report β 4th week of Marchπ
π Unauthorized external access exploited a warehouse system vulnerability at a Japanese automaker
π INC Ransom claims theft of about 128GB of data from a South Korean steel company
π The operator of cybercrime forum LeakBase was arrested
#Cybersecurity #Ransomware #TI
Larva-26002 threat actors have been continuously targeting improperly managed MS-SQL servers. In recent attacks, a scanner malware called ICE Cloud Client, written in Go, has been observed.
Check how Larva-26002 carries out its attack.
https://t.co/ygMLwxfXyK
π AhnLab TIP Weekly Report β 3rd week of Marchπ
π Emerging threat actor CipherForce claimed an attack on a South Korean job portal
πΎ Infrastructure of a new threat actor Loki was exposed
π Cybercrime forum LeakBase was seized and shut down by international law enforcement
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report β 2nd week of Marchπ
π Qilin listed a dermatology clinic and the Korean branch of a global advertising company as victims
π’ KillSec and Everest claimed attacks on a Korean expo management platform and a major elevator manufacturer
π§ Root access to a South Korean government server is being sold on a cybercrime forum
#Cybersecurity #Ransomware #TI
π AhnLab TIP Weekly Report - 1st Week of March π
π¦Ή Ransomware group Morpheus exposes plating company and leaks design drawings and internal credentials
π Ransomware group Ailock resumes activity and re-posts past victim cases
π Pro-Iran/pro-Islamist hacktivists claim DDoS attacks on Israeli defense infrastructure and expand targets to Western nations
#Cybersecurity #TI #ThreatIntel
π AhnLab TIP Weekly Report β 4th week of February
π§Ύ Source code of a South Korean accounting automation firm was found for sale on a cybercrime forum
πΎ Beast ransomware listed two South Korean companies as victims
π Atomsilo ransomware resurfaced with five victims posted
#Cybersecurity #Ransomware #TI