October 2024 Security Issues in Korean & Global Financial Sector

October 2024 Security Issues in Korean & Global Financial Sector

This report comprehensively covers real-world cyber threats and security issues that have occurred in the financial industry both in Korea and abroad. This article includes an analysis of malware and phishing cases distributed to the financial industry. It also provides a list of the top 10 malware strains targeting the

Analysis Report on the Latest Attack Cases  by Kimsuky Group Exploiting  PebbleDash and RDP Wrapper

Analysis Report on the Latest Attack Cases by Kimsuky Group Exploiting PebbleDash and RDP Wrapper

Analysis Overview AhnLab SEcurity intelligence Center (ASEC) recently identified that the Kimsuky group is using the backdoor PebbleDash and RDP Wrapper in multiple attacks. The threat actor uses LNK during initial access to install PowerShell malware on the infected system. Once this process is complete, they install custom-made remote control

WrnRAT Distributed Under the Guise of Gambling Games

WrnRAT Distributed Under the Guise of Gambling Games

AhnLab SEcurity intelligence Center (ASEC) recently discovered that malware was being distributed under the guise of gambling games such as badugi, 2-player go-stop, and hold’em. The threat actor created a website disguised as a gambling game site, and if the game launcher is downloaded, it installs malware that can control

Warning Against Phishing Emails Impersonating Major Korean Entertainment Agencies

Warning Against Phishing Emails Impersonating Major Korean Entertainment Agencies

AhnLab SEcurity Intelligence Center (ASEC) releases weekly and quarterly phishing email statistical reports on the ASEC blog, with fake login, delivery, and purchase order request types being the most common. However, it has been confirmed that phishing emails impersonating major Korean entertainment agencies have recently been distributed in Korea. The

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases in September 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases in September 2024

This report comprehensively covers actual cyber threats and related security issues that have occurred targeting domestic and foreign financial companies. It includes analysis of malware and phishing cases distributed targeting the financial sector, presents the top 10 major malware targeting the financial sector, and also provides industry statistics on domestic

Distribution of SectopRAT (ArechClient2) Disguised as Notion Installer

Distribution of SectopRAT (ArechClient2) Disguised as Notion Installer

Notion is a collaboration tool providing features to manage projects and record them, used by many worldwide. Such popular programs may become targeted by threat actors since attackers can create web pages uploaded with malware strains that pretend to offer legitimate programs.   Users may end up downloading malware when

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases  in August 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases in August 2024

This report comprehensively covers actual cyber threats and related security issues that have occurred targeting domestic and foreign financial companies. It includes analysis of malware and phishing cases distributed targeting the financial sector, presents the top 10 major malware targeting the financial sector, and also provides industry statistics on domestic

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases  in July 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web Cases in July 2024

This report comprehensively covers actual cyber threats and related security issues that have occurred targeting domestic and foreign financial companies. It includes analysis of malware and phishing cases distributed targeting the financial sector, presents the top 10 major malware targeting the financial sector, and also provides industry statistics on domestic

SnakeKeylogger Malware Detected by AhnLab EDR

SnakeKeylogger Malware Detected by AhnLab EDR

1. Overview SnakeKeylogger, an Infostealer created with .NET, can leak data using emails, FTP, SMTP, or Telegram. The malware has been consistently distributed and was covered in a previous ASEC Blog post. [1] This post will reveal the trace of the malicious behaviors of SnakeKeylogger analyzed in the previous post

Distribution of SnakeKeylogger Malware via Email

Distribution of SnakeKeylogger Malware via Email

AhnLab SEcurity intelligence Center (ASEC) has recently identified cases where the SnakeKeylogger malware is being distributed via email. SnakeKeylogger is an Infostealer type of malware developed using the .NET language, and it is characterized by its methods of data exfiltration through email, FTP, SMTP, or Telegram. Figure 1. Phishing email