Aug. 7, 2023, 10:06 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

By Tom Hegel and Aleksandar Milenkoski 


Executive Summary



  • SentinelLabs identified an intrusion into the Russian defense industrial base, specifically a missile engineering organization NPO Mashinostroyeniya.

  • Our findings identify two instances of North Korea related compromise of sensitive internal IT infrastructure within this same Russian DIB organization, including a specific email server, alongside use of a Windows backdoor dubbed OpenCarrot.

  • Our analysis attributes the email server compromise to the ScarCruft threat actor. We also identify the separate use of a Lazarus …

arms base compromise defense defense industrial base dib engineering executive findings identify industrial industrial base infrastructure internal intrusion it infrastructure korea malware analysis missile north north korea organization russian sentinellabs tom hegel

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)