Lazarus APT adds new Vyveva backdoor to its malware arsenal
The malware was first observed in a June 2020 attack, however, it appears that Lazarus has been using malware since at least December 2018.
The malware was first observed in a June 2020 attack, however, it appears that Lazarus has been using malware since at least December 2018.
At least in one case, a ransomware attack resulted in a temporary shutdown of the industrial process at a manufacturing plant.
The PHP maintainer said that the team no longer believes the git.php.net server was compromised.
The investigation into the incident is still ongoing but so far no major information breach has been detected.
The researchers believe that the stolen data likely came from a breach of the now-defunct online gift card shop Cardpool.
APT-C-23 was previously observed impersonating women in cyber-espionage campaigns.
It appears that Facebook CEO Mark Zuckerberg has also been affected by the data leak.
To prevent such attacks organizations are advised to immediately patch CVEs 2018-13379, 2020-12812, and 2019-5591.
The campaign involves the DLL side-loading infection chain used to deliver the FoundCore RAT.
The Ragnarok operators claim to have stolen nearly 40GB of Boggi Milano’s corporate data.
Showing elements 3331 - 3340