Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Researchers Link New NOKKI Malware to North Korean Actor
#1
Quote:A recently observed variant of the KONNI malware appears tied to a remote access Trojan (RAT) previously attributed to a North Korean actor, Palo Alto Networks security researchers say.

In a report published this week, Palo Alto Networks reveals that NOKKI is related to the DOGCALL malware family, a backdoor previously attributed to the Reaper group and likely in use by this group only. The actor is known for targeting the military and defense industry within South Korea, as well as a Middle Eastern organization doing business with North Korea.

By analyzing malicious macros within Microsoft Word documents designed to drop NOKKI, the researchers discovered that the employed deobfuscation technique was also used in documents targeting individuals interested in the World Cup hosted in Russia in 2018 with the DOGCALL malware.

Source: https://www.securityweek.com/researchers...rean-actor
[-] The following 2 users say Thank You to silversurfer for this post:
  â€˘ harlan4096, wwd
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
nternet Download Manager 6.42 Build 9
Changes in 6.42 Bu...harlan4096 — 06:45
Ubuntu 24.04 LTS / 23.10
Ubuntu 24.04 LTS /...harlan4096 — 06:44
Mozilla Thunderbird 125.0
Mozilla Thunderbir...harlan4096 — 06:43
AMD Radeon Software Adrenalin 24.4.1
Highlights New ...harlan4096 — 06:41
AV-TEST - Cybersecurity: Defense Against...
AV-TEST - Cybersec...harlan4096 — 06:40

[-]
Birthdays
Today's Birthdays
avatar (49)steakelask
avatar (43)Termoplenka
Upcoming Birthdays
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>