ASEC Weekly Phishing Email Threat Trends (May 14th, 2023 – May 20th, 2023)

ASEC Weekly Phishing Email Threat Trends (May 14th, 2023 – May 20th, 2023)

AhnLab Security Emergency response Center (ASEC) monitors phishing email threats with the ASEC automatic sample analysis system (RAPIT) and honeypot. This post will cover the cases of distribution of phishing emails during the week from May 14th, 2023 to May 20th, 2023 and provide statistical information on each type. Generally,

Tracking Process Hollowing Malware Using EDR

Tracking Process Hollowing Malware Using EDR

AhnLab Security Emergency response Center (ASEC) once released a report on the types and distribution trends of .NET packers as shown in the post below. As indicated in the report, most .NET packers do not create actual malicious executables hidden via packing features in the local path, injecting malware in

Tracking Traces of Malware Disguised as Hancom Office Document File and Being Distributed (RedEyes)

Tracking Traces of Malware Disguised as Hancom Office Document File and Being Distributed (RedEyes)

AhnLab Security Emergency response Center (ASEC) has confirmed the distribution of malware disguised as Hancom Office document files. The malware that is being distributed is named “Who and What Threatens the World (Column).exe” and is designed to deceive users by using an icon that is similar to that of Hancom

Analysis of Attack Cases: From Korean VPN Installations to MeshAgent Infections

Analysis of Attack Cases: From Korean VPN Installations to MeshAgent Infections

AhnLab Security Emergency response Center (ASEC) has previously covered the case where SparkRAT was distributed contained within a Korean VPN’s installer in the post, “SparkRAT Being Distributed Within a Korean VPN Installer”[1]. This VPN was commonly installed by Chinese users who required better access to the Internet, and the problem

ASEC Weekly Phishing Email Threat Trends (May 7th, 2023 – May 13th, 2023)

ASEC Weekly Phishing Email Threat Trends (May 7th, 2023 – May 13th, 2023)

AhnLab Security Emergency response Center (ASEC) monitors phishing email threats with the ASEC automatic sample analysis system (RAPIT) and honeypot. This post will cover the cases of distribution of phishing emails during the week from May 7th, 2023 to May 13th, 2023 and provide statistical information on each type. Generally,

StrelaStealer Being Distributed To Spanish Users

StrelaStealer Being Distributed To Spanish Users

AhnLab Security Emergency response Center (ASEC) analysis team has recently confirmed the StrelaStealer Infostealer being distributed to Spanish users. StrelaStealer was initially discovered around November 2022 and has been distributed as an attachment to spam emails. In the past, ISO files were used as attachments, but recently, ZIP files have

DarkCloud Infostealer Being Distributed via Spam Emails

DarkCloud Infostealer Being Distributed via Spam Emails

AhnLab Security Emergency response Center (ASEC) has recently discovered the DarkCloud malware being distributed via spam email. DarkCloud is an Infostealer that steals account credentials saved on infected systems, and the threat actor installed ClipBanker alongside DarkCloud. 1. Distribution Method The threat actor sent the following email to induce users

Lazarus Group Targeting Windows IIS Web Servers

Lazarus Group Targeting Windows IIS Web Servers

AhnLab Security Emergency response Center (ASEC) has recently confirmed the Lazarus group, a group known to receive support on a national scale, carrying out attacks against Windows IIS web servers. Ordinarily, when threat actors perform a scan and find a web server with a vulnerable version, they use the vulnerability

Kimsuky Group’s Phishing Attacks Targetting North Korea-Related Personnel

Kimsuky Group’s Phishing Attacks Targetting North Korea-Related Personnel

AhnLab Security Emergency response Center (ASEC) has recently discovered that the Kimsuky group had created a webmail website that looks identical to certain national policy research institutes. Earlier this year, ASEC had covered similar issues in the posts ‘Web Page Disguised as a Kakao[1]/Naver[2] Login Page’. The previous attacker set

Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers

Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers

AhnLab Security Emergency response Center (ASEC) has recently discovered the case of Remcos RAT being installed on poorly managed MS-SQL servers. Unlike the past attack, the recent case showed the threat actor using sqlps to distribute the malware. Sqlps is SQL Server PowerShell and is included in the SQL Server installation