Distribution of SnakeKeylogger Malware via Email

Distribution of SnakeKeylogger Malware via Email

AhnLab SEcurity intelligence Center (ASEC) has recently identified cases where the SnakeKeylogger malware is being distributed via email. SnakeKeylogger is an Infostealer type of malware developed using the .NET language, and it is characterized by its methods of data exfiltration through email, FTP, SMTP, or Telegram. Figure 1. Phishing email

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web in May 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web in May 2024

Statistics on Malware Distributed to Financial Sector Statistics on Korean Accounts Exfiltrated Via Telegram by Industry   MD5 0880757f5b51656408c82fb711fc6f68 088b74f4e87aebbc195f3f17a857eef9 2fde0e06e525e4bccd440a098048a453 45ed98fba139350af5022567dcb6ff10 5c53639753a4e974294f8860302d8bac

Analysis of APT Attack Cases Using Dora RAT Against Korean Companies (Andariel Group)

Analysis of APT Attack Cases Using Dora RAT Against Korean Companies (Andariel Group)

AhnLab SEcurity intelligence Center (ASEC) has recently discovered Andariel APT attack cases against Korean corporations and institutes. Targeted organizations included educational institutes and manufacturing and construction businesses in Korea. Keylogger, Infostealer, and proxy tools on top of the backdoor were utilized for the attacks. The threat actor probably used these

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases  in April 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases in April 2024

Statistics on Malware Distributed to Financial Sectors     Statistics on Korean Accounts Exfiltrated Via Telegram by Industry     Phishing Email Distribution Cases Targeting the Financial Sector   Case 1. Targeting Yuanta Securities employees using the guise of product orders Impersonation target – Product order How the phishing attack

Distribution of Infostealer Made With Electron

Distribution of Infostealer Made With Electron

AhnLab SEcurity intelligence Center (ASEC) has discovered an Infostealer strain made with Electron. Electron is a framework that allows one to develop apps using JavaScript, HTML, and CSS. Discord and Microsoft VSCode are major examples of applications made with Electron. Apps made with Electron are packaged and usually distributed in

Statistics Report on Malware Threat in Q1 2024

Statistics Report on Malware Threat in Q1 2024

Overview  AhnLab uses the automatic analysis system RAPIT to categorize and respond to malware collected through a variety of routes. This report categorizes and shares statistics on known malware among the ones collected during Q1 2024. The malware included in the statistics are in the executable format. These were reported

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases  in March 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases in March 2024

Statistics on Malware Distributed to Financial Sectors   Statistics on Korean Accounts Exfiltrated Via Telegram by Industry   Phishing Email Distribution Cases Targeting the Financial Sector   Case 1. Targeting Korea Investment & Securities Co., Ltd. employees by disguising as a voice mail Impersonation target Voice mail How the Phishing

Threat Actors Hack YouTube Channels to Distribute Infostealers (Vidar and LummaC2)

Threat Actors Hack YouTube Channels to Distribute Infostealers (Vidar and LummaC2)

AhnLab SEcurity intelligence Center (ASEC) recently found that there are a growing number of cases where threat actors use YouTube to distribute malware. The attackers do not simply create YouTube channels and distribute malware—they are stealing well-known channels that already exist to achieve their goal. In one of the cases,

Infostealers Extorting Web Browser Account Credentials Detected by AhnLab EDR

Infostealers Extorting Web Browser Account Credentials Detected by AhnLab EDR

Web browsers are some of the programs most commonly and frequently used by PC users. Users generally use browsers to look up information, send and receive emails, and use web services such as shopping. This is the case for both individual users and employees conducting business in companies. To use