Threat Trend Report on APT Attacks (South Korea) – April 2024 Major Issues on APT Attacks Against South Korea

Threat Trend Report on APT Attacks (South Korea) – April 2024 Major Issues on APT Attacks Against South Korea

Overview   AhnLab has been using AhnLab Smart Defense (ASD) to monitor advanced persistent threat (APT) attacks against targets in South Korea. This report discusses the categorization and statistics of APT attacks against Korean targets in April 2024 as well as the features of each type.   Figure 1. Statistics

Security Update Advisory for TunnelVision Attack (CVE-2024-3661)

Overview   A mitigation has been released to address the vulnerability caused by the TunnelVision...

WordPress LiteSpeed Cache and Icegram Express plugin security update advisory

Overview   We have released updates to fix vulnerabilities in the WordPress LiteSpeed Cache and...

F5 Product Security Update Advisory

Overview   We have released updates to fix vulnerabilities in F5 products. users of affected...

Tinyproxy Product Security Update Advisory (CVE-2023-49606)

Overview   We have released an update to address a vulnerability in our Tinyproxy product....

Distribution of Malware Under the Guise of MS Office Cracked Versions (XMRig, OrcusRAT, etc.)

Distribution of Malware Under the Guise of MS Office Cracked Versions (XMRig, OrcusRAT, etc.)

Through a post titled “Orcus RAT Being Distributed Disguised as a Hangul Word Processor Crack” [1], AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which a threat actor distributed RAT and CoinMiner to Korean users. Until recently, the attacker created and distributed various malware strains, such as

Threat Trend Report on APT Groups – April 2024 Major Issues on APT Groups

Threat Trend Report on APT Groups – April 2024 Major Issues on APT Groups

The cases of major APT groups for April 2024 gathered from materials made public by security companies and institutions are as follows.   1)  APT28 (Forest Blizzard)   Microsoft Threat Intelligence released the results of the investigation on the activities of APT28, a Russia-based threat actor.[1] This group has been

Threat Trend Report on Deep Web &Dark Web – Ransomware Groups & Cybercrime Forums and Markets in April 2024

Threat Trend Report on Deep Web &Dark Web – Ransomware Groups & Cybercrime Forums and Markets in April 2024

Notice  This trend report on the deep web and dark web of March 2024 is sectioned into Ransomware, Forums & Black Markets, and Threat Actors. We would like to state beforehand that some of the content has yet to be confirmed to be true.   Major Issues   1) Ransomware