Malware Being Distributed Disguised as a Job Application Letter

Malware Being Distributed Disguised as a Job Application Letter

AhnLab Security Emergency response Center (ASEC) has identified that malware disguised as a job application letter is continuously being distributed. This malware is equipped with a feature that checks for the presence of various antivirus processes including a process with AhnLab’s product name (V3Lite.exe) and is being distributed through malicious

Tracking Process Hollowing Malware Using EDR

Tracking Process Hollowing Malware Using EDR

AhnLab Security Emergency response Center (ASEC) once released a report on the types and distribution trends of .NET packers as shown in the post below. As indicated in the report, most .NET packers do not create actual malicious executables hidden via packing features in the local path, injecting malware in

Tracking Traces of Malware Disguised as Hancom Office Document File and Being Distributed (RedEyes)

Tracking Traces of Malware Disguised as Hancom Office Document File and Being Distributed (RedEyes)

AhnLab Security Emergency response Center (ASEC) has confirmed the distribution of malware disguised as Hancom Office document files. The malware that is being distributed is named “Who and What Threatens the World (Column).exe” and is designed to deceive users by using an icon that is similar to that of Hancom

Analysis of Attack Cases: From Korean VPN Installations to MeshAgent Infections

Analysis of Attack Cases: From Korean VPN Installations to MeshAgent Infections

AhnLab Security Emergency response Center (ASEC) has previously covered the case where SparkRAT was distributed contained within a Korean VPN’s installer in the post, “SparkRAT Being Distributed Within a Korean VPN Installer”[1]. This VPN was commonly installed by Chinese users who required better access to the Internet, and the problem

StrelaStealer Being Distributed To Spanish Users

StrelaStealer Being Distributed To Spanish Users

AhnLab Security Emergency response Center (ASEC) analysis team has recently confirmed the StrelaStealer Infostealer being distributed to Spanish users. StrelaStealer was initially discovered around November 2022 and has been distributed as an attachment to spam emails. In the past, ISO files were used as attachments, but recently, ZIP files have

DarkCloud Infostealer Being Distributed via Spam Emails

DarkCloud Infostealer Being Distributed via Spam Emails

AhnLab Security Emergency response Center (ASEC) has recently discovered the DarkCloud malware being distributed via spam email. DarkCloud is an Infostealer that steals account credentials saved on infected systems, and the threat actor installed ClipBanker alongside DarkCloud. 1. Distribution Method The threat actor sent the following email to induce users

Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers

Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers

AhnLab Security Emergency response Center (ASEC) has recently discovered the case of Remcos RAT being installed on poorly managed MS-SQL servers. Unlike the past attack, the recent case showed the threat actor using sqlps to distribute the malware. Sqlps is SQL Server PowerShell and is included in the SQL Server installation

Infostealer Being Distributed to Japanese Users

Infostealer Being Distributed to Japanese Users

AhnLab Security Emergency response Center (ASEC) has recently discovered Infostealers disguised as an adult game being distributed to Japanese users. Although the distribution route has not been confirmed as of yet, it can be assumed that the Infostealers are being distributed via torrent or illegal file-sharing websites since it is

LokiLocker, a Ransomware Similar to BlackBit Being Distributed in Korea

LokiLocker, a Ransomware Similar to BlackBit Being Distributed in Korea

AhnLab Security Emergency response Center(ASEC) has confirmed the distribution of the LokiLocker ransomware in Korea. This ransomware is almost identical to the BlackBit ransomware and their common traits have been mentioned before in a previous blog post. A summary of these similarities is as follows. Similarities Between LokiLocker and BlackBit

Chinese Hacker Group Stealing Information From Korean Companies

Chinese Hacker Group Stealing Information From Korean Companies

Recently, there have been frequent cases of attacks targeting vulnerable servers that are accessible externally, such as SQL servers or IIS web servers. The team has confirmed two affected companies in this case. One being a company for semiconductors, and the other being a smart manufacturing company which utilizes artificial