Summary: 2025/04/25 22:09

First reported date: 2024/07/18
Inquiry period : 2025/03/26 22:09 ~ 2025/04/25 22:09 (1 months), 10 search results

전 기간대비 신규 트렌드를 보이고 있습니다.
악성코드 유형
RAT NetWireRC Trojan 도 새롭게 확인됩니다.
공격자 Lazarus 도 새롭게 확인됩니다.
공격기술 Campaign ClickFix Phishing ClearFake 도 새롭게 확인됩니다.
기관 및 기업 North Korea dprk AhnLab SECUI Kaspersky Russia 도 새롭게 확인됩니다.
기타 BeaverTail Malware cti Tropidoor Email 등 신규 키워드도 확인됩니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/05 North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
    ㆍ 2025/04/03 BeaverTail and Tropidoor Malware Distributed via Recruitment Emails
    ㆍ 2025/04/02 BeaverTail and Tropidoor Malware Distributed via Recruitment Emails

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1BeaverTail 10 ▲ new
2Malware 8 ▲ new
3North Korea 8 ▲ new
4cti 5 ▲ new
5Tropidoor 5 ▲ new
6dprk 5 ▲ new
7Campaign 4 ▲ new
8Email 4 ▲ new
9AhnLab 3 ▲ new
10Victim 2 ▲ new
11npm 2 ▲ new
12contagiousinterview 2 ▲ new
13Recruitment 2 ▲ new
14North 2 ▲ new
15RAT 2 ▲ new
16Distribution 2 ▲ new
17NetWireRC 2 ▲ new
18Korean 2 ▲ new
19Distributed 2 ▲ new
20project 2 ▲ new
21SECUI 2 ▲ new
22Interview 1 ▲ new
23Contagious 1 ▲ new
24ClickFix 1 ▲ new
25famouschollima 1 ▲ new
26ottercookie 1 ▲ new
27Infrastructure 1 ▲ new
28Kaspersky 1 ▲ new
29Russia 1 ▲ new
30Launches 1 ▲ new
31Operation 1 ▲ new
32Role 1 ▲ new
33Crucial 1 ▲ new
34Plays 1 ▲ new
35invisibleferret 1 ▲ new
36voiddokkaebi 1 ▲ new
37Russian 1 ▲ new
38frostyferret 1 ▲ new
39Malicious 1 ▲ new
40Expands 1 ▲ new
41Lazarus 1 ▲ new
42case 1 ▲ new
43Deploy 1 ▲ new
44Hackers 1 ▲ new
45community 1 ▲ new
46채용 1 ▲ new
47Trojan 1 ▲ new
48메일 1 ▲ new
49위장 1 ▲ new
50Phishing 1 ▲ new
51ClearFake 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
RAT
2 (40%)
NetWireRC
2 (40%)
Trojan
1 (20%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
Lazarus
1 (100%)
Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Campaign
4 (57.1%)
ClickFix
1 (14.3%)
Phishing
1 (14.3%)
ClearFake
1 (14.3%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
North Korea
8 (40%)
dprk
5 (25%)
AhnLab
3 (15%)
SECUI
2 (10%)
Kaspersky
1 (5%)
Threat info
Last 5

SNS

(Total : 7)
  Total keyword

North Korea Malware dprk Campaign AhnLab Email SECUI ClickFix Kaspersky Russia Operation NetWireRC Lazarus Distribution RAT Attacker Phishing ClearFake

No Title Date
1lazarusholic @lazarusholic
"Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations" published by @trendmicro. #BeaverTail, #FrostyFerret, #VoidDokkaebi, #DPRK, #CTI https://t.co/7tOvhUerrV
2025.04.24
2lazarusholic @lazarusholic
"Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware" published by @silentpush. #BeaverTail, #ContagiousInterview, #InvisibleFerret, #OtterCookie, #FamousChollima, #ClickFix, #DPRK, #CTI https://t.co/uUEkpODoUq
2025.04.24
3lazarusholic @lazarusholic
"Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads" published by @SocketSecurity. #BeaverTail, #ContagiousInterview, #Lazarus, #NPM, #DPRK, #CTI https://t.co/sZKO4sicWJ
2025.04.06
4The Hacker News @TheHackersNews
???? North Korean hackers are hunting developers—right now. New malware-laced npm packages (5,600+ downloads) are spreading BeaverTail and a new RAT loader, hidden as fake utilities. ???? Targets? Your code. Your system. Your data. Read: https://t.co/JKVme9mdYP
2025.04.05
5Virus Bulletin @virusbtn
AhnLab researchers investigate the BeaverTail and Tropidoor malware distributed via recruitment emails suspected to be part of a campaign carried out by North Korean attackers. https://t.co/tGMLzlkccC https://t.co/Sc8fNmidTO
2025.04.04

Additional information

No data
No data
No data
No URL CC ASN Co Reporter Date
1http://45.43.11.201:1244/pdown
APT BeaverTail Lazarus python StrelaStealer
US USPacket Flip, LLCDaveLikesMalwre2024.12.12
2http://147.124.197.138:1244/pdown
APT BeaverTail Lazarus python StrelaStealer
US USAC-AS-1DaveLikesMalwre2024.12.12
3http://66.235.168.232:1244/pdown
APT BeaverTail Lazarus python StrelaStealer
US USTIER-NETDaveLikesMalwre2024.12.12
4http://38.92.47.85:1244/pdown
APT BeaverTail Lazarus python StrelaStealer
US USCOGENT-174DaveLikesMalwre2024.12.12
5http://38.92.47.151:1244/pdown
APT BeaverTail Lazarus python StrelaStealer
US USCOGENT-174DaveLikesMalwre2024.12.12
View only the last 5
Beta Service, If you select keyword, you can check detailed information.