mirror of
https://github.com/blackorbird/APT_REPORT.git
synced 2025-06-12 02:04:17 +00:00
threat summary report
ddos q2
https://gcorelabs.com/blog/ddos-attack-trends-in-q1q2-of-2022/
Spam and phishing in 2021
https://securelist.com/spam-and-phishing-in-2021/105713/
list:
- https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/
- https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/
- https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/
- https://blogs.jpcert.or.jp/en/2021/01/Lazarus_malware2.html
- http://blog.nsfocus.net/stumpzarus-apt-lazarus/
- https://blog.malwarebytes.com/awareness/2021/02/north-korean-hackers-charged-with-1-3-billion-of-cyberheists/
- https://securelist.com/lazarus-threatneedle/100803/
- https://blog.sygnia.co/lazarus-groups-mata-framework-leveraged-to-deploy-tflower-ransomware?hsLang=en
- https://blogs.jpcert.or.jp/en/2021/03/Lazarus_malware3.html
- https://www.welivesecurity.com/2021/04/08/are-you-afreight-dark-watch-out-vyveva-new-lazarus-backdoor/
- https://blog.group-ib.com/btc_changer
- https://blog.malwarebytes.com/threat-intelligence/2021/04/lazarus-apt-conceals-malicious-code-within-bmp-file-to-drop-its-rat/
- https://www.estsecurity.com/enterprise/security-center/notice/view/59449?category-id=
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/lazarus-recruitment/
- https://ti.qianxin.com/blog/articles/Analysis-of-attacks-by-Lazarus-using-Daewoo-shipyard-as-bait/
- https://mp.weixin.qq.com/s/MBH8ACSTfC6UGzf2h1BuhA
- https://cybersecurity.att.com/blogs/labs-research/lazarus-campaign-ttps-and-evolution
- https://ti.qianxin.com/blog/articles/Lazarus'-Recent-Attack-Campaign-Targeting-Blockchain-Finance-and-Energy-Sectors/
- https://securelist.com/apt-trends-report-q3-2021/104708/
- https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities
- https://asec.ahnlab.com/ko/28527/
- https://twitter.com/esetresearch/status/1458438155149922312
- https://mp.weixin.qq.com/s/ZMnO3Q6MAxafmOOO2cQMfw
- https://www.nknews.org/pro/dprk-hackers-use-south-korean-servers-and-google-drive-to-hide-malware-attack/
- https://blog.alyac.co.kr/3489
- https://blog.alyac.co.kr/3525
- https://blog.alyac.co.kr/3536
- https://blog.alyac.co.kr/3550
- https://www.estsecurity.com/enterprise/security-center/notice/view/22734?category-id=5
- https://blog.alyac.co.kr/3624
- https://apt.360.cn/report/apts/171.html
- https://ti.qianxin.com/blog/articles/Analysis-on-the-attack-activities-of-Kimsuky-APT-using-the-Foreign-Ministry-of-South-Korea-as-bait/
- https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/
- https://www.freebuf.com/articles/paper/278762.html
- https://mp.weixin.qq.com/s/y4TGzrhr2rvVk5EAca91hA
- https://asec.ahnlab.com/ko/25351/
- https://www.freebuf.com/articles/paper/281985.html
- https://mp.weixin.qq.com/s/BvP00a-33OOmbcdwDkeqeg
- https://www.boannews.com/media/view.asp?idx=99543
- https://www.boannews.com/media/view.asp?idx=99543
- https://inquest.net/blog/2021/08/23/kimsuky-espionage-campaign
- https://blog.alyac.co.kr/4130
- https://asec.ahnlab.com/ko/27166/
- https://mp.weixin.qq.com/s/sautIOi__PCf4Y_tfdj1zg
- https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html%EF%BB%BF
- https://blog.malwarebytes.com/threat-analysis/2021/01/retrohunting-apt37-north-korean-apt-used-vba-self-decode-technique-to-inject-rokrat/
- https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/
- https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/
- https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-inkysquid-deploys-rokrat/
- https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/
- https://mp.weixin.qq.com/s/nyxZFXgrtm2-tBiV3-wiMg
- https://www.anomali.com/blog/primitive-bear-gamaredon-targets-ukraine-with-timely-themes
- https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/
- https://blog.netlab.360.com/rotajakiro_vs_oceanlotus_cn/
- https://ti.qianxin.com/blog/articles/Operation-OceanStorm:The-OceanLotus-hidden-under-the-abyss-of-the-deep/
- https://www.amnestyusa.org/reports/vietnamese-activists-targeted-by-notorious-hacking-group/
- https://mp.weixin.qq.com/s/WnKc0JbjA5_IsjPFSzFoYA
- https://mp.weixin.qq.com/s/NUjR3qVE0PJXULgGc3Edow
- https://mp.weixin.qq.com/s/8nP27nQKD_6OE-igggFDww
- https://www.4hou.com/posts/2Drj
- https://ti.qianxin.com/blog/articles/%22operation-magichm%22:CHM-file-release-and-subsequent-operation-of-BITTER-organization/
- https://ti.qianxin.com/blog/articles/Donot-uses-Google-Drive-to-distribute-malware/
- https://ti.qianxin.com/blog/articles/Analysis-of-the-Donot-group's-attack-campaign-using-RTF-template-injection-against-the-neighbourhood/
- https://mp.weixin.qq.com/s/RC1S7yrYT-o9oyPHkPE-ow
- https://ti.qianxin.com/blog/articles/Sidecopy-dual-platform-weapon/
- https://mp.weixin.qq.com/s/C09P0al1nhsyyujHRp0FAw
- https://ti.dbappsecurity.com.cn/blog/articles/2021/02/10/windows-kernel-zero-day-exploit-is-used-by-bitter-apt-in-targeted-attack-cn/
- https://resources.lookout.com/blog/lookout-discovers-novel-confucius-apt-android-spyware-linked-to-india-pakistan-conflict
- https://www.antiy.com/response/20210222.html
- https://mp.weixin.qq.com/s/ELYDvdMiiy4FZ3KpmAddZQ
- https://blog.cyble.com/2021/04/21/donot-team-apt-group-is-back-to-using-old-malicious-patterns/
- https://blog.talosintelligence.com/2021/05/transparent-tribe-infra-and-targeting.html
- https://ti.qianxin.com/blog/articles/SideWinder-arsenal-update:Analysis-of-attack-activity-against-Pakistan-using-foreign-policy/
- https://ti.qianxin.com/blog/articles/Analysis-of-the-APT-Group-Donot's-Attack-Campaign-Using-the-Impact-of-the-Afghan-Withdrawal-as-Bait/
- https://ti.qianxin.com/blog/articles/Analysis-of-recent-attacks-by-Transparent-Tribe-using-Indian-Defense-Ministry-meeting-minutes-as-bait/
- https://www.trendmicro.com/en_us/research/21/h/confucius-uses-pegasus-spyware-related-lures-to-target-pakistani.html
- https://mp.weixin.qq.com/s/_LHJYgf6l9uFYMN23fUQAA
- https://mp.weixin.qq.com/s/AhxP5HmROtMsFBiUxj0cFg
- https://blog.cyble.com/2021/09/14/apt-group-targets-indian-defense-officials-through-enhanced-ttps/
- https://www.amnesty.org/en/latest/news/2021/10/togo-activist-targeted-with-spyware-by-notorious-hacker-group/
- https://ti.qianxin.com/blog/articles/Analysis-of-BITTER-APT-Group-for-the-Military-Industry-New-Attack-Activity/
- https://mp.weixin.qq.com/s/CGHDuJAb4dav_th25yYpWA
- https://mp.weixin.qq.com/s/MQgEVZVqQmcyOXVlEgpezA
- http://blog.nsfocus.net/apt-sidecopy/
- https://blog.malwarebytes.com/threat-intelligence/2021/12/sidecopy-apt-connecting-lures-to-victims-payloads-to-infrastructure/
- https://ti.qianxin.com/blog/articles/SideCopy-APT-Group-Takes-Advantage-of-the-Fire/
- https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf
- https://unit42.paloaltonetworks.com/ironnetinjector
- https://ti.qianxin.com/blog/articles/Analysis-of-attack-activities-of-APT28-using-high-carbon-ferrochrome-manufacturer-registration-form-as-bait/
- https://blog.talosintelligence.com/2021/02/gamaredonactivities.html
- https://www.mimecast.com/incident-report/
- https://www.spiegel.de/politik/deutschland/russischer-hack-erneute-attacke-hack-auf-bundestag-sieben-abgeordnete-betroffen-a-75e1adbe-4462-4e30-bd94-96796aed6b8a
- https://www.anomali.com/blog/primitive-bear-gamaredon-targets-ukraine-with-timely-themes
- https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/
- https://msrc-blog.microsoft.com/2021/06/25/new-nobelium-activity/
- https://www.version2.dk/artikel/danmarks-nationalbank-hacket-led-verdens-mest-sofistikerede-hackerangreb-1092886
- https://mp.weixin.qq.com/s/bJrEwoq4QkDJvEk_ThvueQ
- https://www.bloomberg.com/news/articles/2021-07-06/russian-state-hackers-breached-republican-national-committee
- https://www.zscaler.com/blogs/security-research/cloudfall-targets-researchers-and-scientists-invited-international-military
- https://blog.talosintelligence.com/2021/09/tinyturla.html
- https://services.google.com/fh/files/misc/gcat_threathorizons_full_nov2021.pdf
- http://blog.nsfocus.net/solarwinds-foggyweb/
- https://ti.qianxin.com/blog/articles/MKLG-Operation:Analysis-of-attacks-against-the-Middle-East-for-several-years/
- https://ti.qianxin.com/blog/articles/SnowLeopard:Surveillance-activities-against-Pakistani-users-disclosed/
- https://ti.qianxin.com/blog/articles/PyMICROPSIA-New-Trojan-for-AridViper/
- https://ti.qianxin.com/blog/articles/PROMETHIUM-forged-NotePad++-installation-package-attack-campaign/
- https://ti.qianxin.com/blog/articles/Molerats-Latest-Mobile-Attack-Tracking-Disclosure/
- https://blog.certfa.com/posts/charming-kitten-christmas-gift/
- https://www.anomali.com/blog/probable-iranian-cyber-actors-static-kitten-conducting-cyberespionage-campaign-targeting-uae-and-kuwait-government-agencies
- https://ti.qianxin.com/blog/articles/MKLG-Operation:Analysis-of-attacks-against-the-Middle-East-for-several-years/
- https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/
- https://about.fb.com/wp-content/uploads/2021/04/Technical-threat-report-Arid-Viper-April-2021.pdf
- https://mp.weixin.qq.com/s/o_EVjBVN2sQ1q7cl4rUXoQ
- https://www.trendmicro.com/en_us/research/21/g/strongpity-apt-group-deploys-android-malware-for-the-first-time.html
- https://ti.qianxin.com/blog/articles/SnowLeopard:Surveillance-activities-against-Pakistani-users-disclosed/
- https://securelist.com/lyceum-group-reborn/104586/
- https://ti.qianxin.com/blog/articles/APT-Q-63-Attack-Targeting-Palestinian-Areas-Using-Election-Information-as-Bait/
- https://ti.qianxin.com/blog/articles/PROMETHIUM-forged-NotePad++-installation-package-attack-campaign/
- https://ti.qianxin.com/blog/articles/PyMICROPSIA-New-Trojan-for-AridViper/
- https://ti.qianxin.com/blog/articles/Operation-EICAR:-Targeted-hunting-activities-for-the-securities-and-finance-industry/
- https://ti.qianxin.com/blog/articles/APT-Q-12-Attack-the-Trade-Industry/
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/new-apt-group-chamelgang/#id0
- https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/