Remove archives
article thumbnail

NK-linked InkySquid APT leverages IE exploits in recent attacks

Security Affairs

APT37 has been active since at least 2012, it mainly targeted government, defense, military, and media organizations in South Korea. Spawn a thread to recursively search a path and upload files as a ZIP archive. The post NK-linked InkySquid APT leverages IE exploits in recent attacks appeared first on Security Affairs.

Metadata 109
article thumbnail

The Platinum APT group adds the Titanium backdoor to its arsenal

Security Affairs

Security experts at Kaspersky Lab have spotted a new backdoor, tracked as Titanium, that was used by the Platinum APT group in attacks in the wild, the malicious code implements sophisticated evasion techniques. The backdoor deploys an SFX archive containing a Windows task installation script. Pierluigi Paganini.

IT 57
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Snowden Ten Years Later

Schneier on Security

He had been working on the Edward Snowden archive for a couple of months, and had a pile of more technical documents that he wanted help interpreting. I didn’t know either of them, but I have been writing about cryptography, security, and privacy for decades. I tried to talk to Greenwald about his own operational security.

article thumbnail

Katyn Massacre Records Show Need to Prioritize Disclosure of Historical Information with Significant Public Interest

Archives Blogs

The prisoners represented a majority of Poland’s governing elite—military, police, and civil society leaders captured in 1939, when the Soviet Union and Nazi Germany invaded and divided Poland by secret diplomatic agreement.

article thumbnail

Russia’s SolarWinds Attack

Schneier on Security

The solution is to prioritize security and defense over espionage and attack. We don’t know how, but last year the company’s update server was protected by the password “solarwinds123” — something that speaks to a lack of security culture.) Do any Russian organizations use Orion? Probably.).

article thumbnail

The return of TA402 Molerats APT after a short pause

Security Affairs

MoleRATs is an Arabic-speaking, politically motivated group of hackers that has been active since 2012, in 2018 monitoring the operation of the group, Kaspersky identified different techniques utilized by very similar attackers in the MENA region. ” Follow me on Twitter: @securityaffairs and Facebook. Pierluigi Paganini.