Lazarus Group - Tagged - Security Boulevard The Home of the Security Bloggers Network Fri, 21 Jul 2023 19:51:33 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Lazarus Group - Tagged - Security Boulevard 32 32 133346385 GitHub Developers Targeted by North Korea’s Lazarus Group https://securityboulevard.com/2023/07/github-developers-targeted-by-north-koreas-lazarus-group/ Fri, 21 Jul 2023 19:51:33 +0000 https://securityboulevard.com/?p=1982351 GitHub satellite cyberattack Strontium cyberwarfare counter-drone The Legality of Waging War in Cyberspace

The Lazarus Group is behind a social engineering campaign that uses repository invitations and malicious npm packages to target developers on GitHub.

The post GitHub Developers Targeted by North Korea’s Lazarus Group appeared first on Security Boulevard.

]]>
1982351
Lazarus Assault Via 3CX Exposes Need to Rethink Security https://securityboulevard.com/2023/04/lazarus-assault-via-3cx-exposes-need-to-rethink-security/ Wed, 12 Apr 2023 12:00:52 +0000 https://securityboulevard.com/?p=1971380 OSINT, Lazarus updates firmware open source Log4j OpenSSF API security dynamic code application

When North Korean threat actors the Lazarus Group exploited a legitimate update to the 3CXDesktopApp—a softphone application from 3CX—security professionals didn’t initially pick up on the import of the activity and tactics that signaled the attack. In fact, according to CrowdStrike, which discovered the attack, even experienced security professionals pooh-poohed detections as false positives. And..

The post Lazarus Assault Via 3CX Exposes Need to Rethink Security appeared first on Security Boulevard.

]]>
1971380
Warning: N. Korean Job Scams Push Trojans via LinkedIn https://securityboulevard.com/2022/09/north-korea-job-scam-trojan-linkedin-richixbw/ Fri, 30 Sep 2022 17:32:02 +0000 https://securityboulevard.com/?p=1940123

Hey, hey, DPRK, how many people will you scam today?

The post Warning: N. Korean Job Scams Push Trojans via LinkedIn appeared first on Security Boulevard.

]]>
1940123
U.S. Indicts North Korean Hackers in Theft of $200 Million https://securityboulevard.com/2021/02/u-s-indicts-north-korean-hackers-in-theft-of-200-million/ Wed, 17 Feb 2021 21:12:56 +0000 https://krebsonsecurity.com/?p=54375 The U.S. Justice Department today unsealed indictments against three men accused of working with the North Korean regime to carry out some of the most damaging cybercrime attacks over the past decade, including the 2014 hack of Sony Pictures, the global WannaCry ransomware contagion of 2017, and the theft of roughly $200 million and attempted theft of more than $1.2 billion from banks and other victims worldwide.

The post U.S. Indicts North Korean Hackers in Theft of $200 Million appeared first on Security Boulevard.

]]>
1873265
Ransomware Victims That Pay Up Could Incur Steep Fines from Uncle Sam https://securityboulevard.com/2020/10/ransomware-victims-that-pay-up-could-incur-steep-fines-from-uncle-sam/ Thu, 01 Oct 2020 16:36:19 +0000 https://krebsonsecurity.com/?p=53169 Companies victimized by ransomware and firms that facilitate negotiations with ransomware extortionists could face steep fines from the U.S. federal government if the crooks who profit from the attack are already under economic sanctions, the Treasury Department warned today.

The post Ransomware Victims That Pay Up Could Incur Steep Fines from Uncle Sam appeared first on Security Boulevard.

]]>
1860797
Lazarus Group May Have Hacked Indian Nuclear Power Plant https://securityboulevard.com/2019/10/lazarus-group-may-have-hacked-indian-nuclear-power-plant/ Thu, 31 Oct 2019 13:28:17 +0000 https://hotforsecurity.bitdefender.com/?p=21716 Authorities from the Nuclear Power Corporation of India Limited (NPCIL) have admitted that malware, believed to originate from the Lazarus Group, infected the administrative network of the Kudankulam Nuclear Power Plant. Initial reports about possible problems with the Kudankulam Nuclear Power Plant (KKNPP) surfaced a couple of days ago when a researcher who used to […]

The post Lazarus Group May Have Hacked Indian Nuclear Power Plant appeared first on Security Boulevard.

]]>
1825163
Jackson County pays ransomware operators $400k to regain access to computers https://securityboulevard.com/2019/03/jackson-county-pays-ransomware-operators-400k-to-regain-access-to-computers/ Mon, 11 Mar 2019 12:05:24 +0000 https://hotforsecurity.bitdefender.com/?p=20939 Officials in Jackson County, a rural area in the southeastern US state of Georgia, were forced over the weekend to pay hackers almost half a million dollars after a ransomware attack brought its entire fleet of computer systems to its knees. According to statescoop.com, the county government’s entire email system was taken offline following the […]

The post Jackson County pays ransomware operators $400k to regain access to computers appeared first on Security Boulevard.

]]>
1802168
North Korean Lazarus Group Starts Targeting Russian Organizations https://securityboulevard.com/2019/02/north-korean-lazarus-group-starts-targeting-russian-organizations/ Wed, 20 Feb 2019 13:13:10 +0000 https://securityboulevard.com/?p=1800237 generative AI network, attack, organizations HEAT attack ransomware threats cyberattacks virtual appliances

In an unusual move, the Lazarus hacking group associated with the North Korean government has recently started targeting organizations from Russia. The group’s primary targets until now have been organizations from countries with which North Korea has geopolitical tensions, such as South Korea, Japan and the United States. Researchers from Check Point Software Technologies found..

The post North Korean Lazarus Group Starts Targeting Russian Organizations appeared first on Security Boulevard.

]]>
1800237
Windows VCF Zero-Day Exploit Allows Remote Code Execution https://securityboulevard.com/2019/01/windows-vcf-zero-day-exploit-allows-remote-code-execution/ Wed, 16 Jan 2019 14:27:08 +0000 https://securityboulevard.com/?p=1797208

A new unpatched vulnerability in Windows has been disclosed along with proof-of-concept exploit code. It could allow hackers to more easily install malware on computers, but it requires user interaction. The vulnerability was discovered by a security researcher named John Page, aka hyp3rlinx, who reported it to Microsoft in August through Trend Micro’s Zero Day..

The post Windows VCF Zero-Day Exploit Allows Remote Code Execution appeared first on Security Boulevard.

]]>
1797208
Cloud Hosting Provider DataResolution.net Battling Christmas Eve Ransomware Attack https://securityboulevard.com/2019/01/cloud-hosting-provider-dataresolution-net-battling-christmas-eve-ransomware-attack/ Wed, 02 Jan 2019 18:32:37 +0000 https://krebsonsecurity.com/?p=46190 Cloud hosting provider Dataresolution.net is struggling to bring its systems back online after suffering a ransomware infestation on Christmas Eve, KrebsOnSecurity has learned. The company says its systems were hit by the Ryuk ransomware, the same malware strain that crippled printing and delivery operations for multiple major U.S. newspapers over the weekend.

The post Cloud Hosting Provider DataResolution.net Battling Christmas Eve Ransomware Attack appeared first on Security Boulevard.

]]>
1796087