×

Register to Access Intelligence Summary

First Name
Last Name
Job Title
Company
Country
State
Thank you!
Error - something went wrong!
   

Weekly Intelligence Summary 10 Apr 2020

April 10, 2020

In the spotlight this week: After a brief period of inactivity, the North Korean threat group “APT37” has been blamed for yet another cyber-espionage campaign involving spearphishing, this time using lures mentioning North Korean refugees.

The March 2020 campaign used cloud-related platforms to distribute malware, evade detection, and minimize the group’s footprint―a popular tactic of APT37. Because the spearphishing emails contained hyperlinks that led to malicious files, the emails were able to bypass many security tools, as there were no attachments to be analyzed and deemed malicious. This campaign marked APT37’s first appearance since Microsoft seized 50 of the group’s web domains in December 2019. Despite that recent setback, the group clearly remains persistent and committed to gathering foreign intelligence.

Previous Report
Weekly Intelligence Summary 17 Apr 2020
Weekly Intelligence Summary 17 Apr 2020

The persistent and financially motivated cybercriminal group “FIN6” has reportedly partnered with the opera...

Next Report
Weekly Intelligence Summary 03 Apr 2020
Weekly Intelligence Summary 03 Apr 2020

The cybercriminal group “FIN7” recently distributed malware via USB flash drives mailed to United States-ba...

×

Want these
Threat Intelligence reports sent straight to your inbox?

Subscribe below!

First Name
Last Name
Company
Country
State- optional
Job Title
Thank you!
Error - something went wrong!