Researchers Link New NOKKI Malware to North Korean Actor
#1
Quote:A recently observed variant of the KONNI malware appears tied to a remote access Trojan (RAT) previously attributed to a North Korean actor, Palo Alto Networks security researchers say.

In a report published this week, Palo Alto Networks reveals that NOKKI is related to the DOGCALL malware family, a backdoor previously attributed to the Reaper group and likely in use by this group only. The actor is known for targeting the military and defense industry within South Korea, as well as a Middle Eastern organization doing business with North Korea.

By analyzing malicious macros within Microsoft Word documents designed to drop NOKKI, the researchers discovered that the employed deobfuscation technique was also used in documents targeting individuals interested in the World Cup hosted in Russia in 2018 with the DOGCALL malware.

Source: https://www.securityweek.com/researchers...rean-actor
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, wwd
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.18  Fixed th...Kool — 07:21
Insta360 Coupon Code 2026 – [INRSGY42P4A...
IntroductionFinding ...Pom121212 — 07:05
Insta360 Coupon Code 2026 – [INRSGY42P4A...
Finding the best Ins...Pom121212 — 07:03
Mozilla Firefox 150 Released With Fixes...
Claude Mythos Expose...harlan4096 — 06:11
Mozilla Firefox 150 Released With Fixes ...
Mozilla has releas...harlan4096 — 06:10

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>