Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.
North Korean hackers build offline AI stack to automate phishing and malware development.
AI가 선별한 아티클
북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.
North Korean hackers build offline AI stack to automate phishing and malware development.
Microsoft 365를 겨냥한 AitM 피싱 공격에 대한 경고.
Warning about AitM phishing attacks targeting Microsoft 365.
FedEx의 결제 문자, 피싱으로 오인된 이유 분석.
Analysis of why FedEx's payment SMS was mistaken for phishing.
Kali365가 마이크로소프트 인증을 악용하여 기업 데이터를 위협하고 있다.
Kali365 weaponizes Microsoft authentication to threaten corporate data access.
Cloudflare의 Wallet 서비스는 피싱 공격과 유사한 보안 이슈를 드러냄.
Cloudflare's Wallet service reveals security issues resembling phishing attacks.
PhaaS 툴킷 Greatness가 MFA를 우회하는 장치 코드 피싱을 추가했습니다.
The PhaaS toolkit Greatness adds device code phishing to bypass MFA.
장치 코드 피싱은 2026년 가장 빠르게 성장하는 위협이다.
Device code phishing is the fastest-growing threat of 2026.
아마존, npm 패키지 해킹을 북한의 사이프리 슬리트와 연결지음.
Amazon links npm package hijack to North Korea's Sapphire Sleet.
Microsoft Teams를 악용한 피싱 캠페인에 대한 경고.
Warning about a phishing campaign exploiting Microsoft Teams.
Cruciferra 크립터가 BYOVD와 프로세스 유령화를 통해 윈도우 악성코드를 숨기는 데 사용됨.
Cruciferra crypter is used with BYOVD and process ghosting to hide Windows malware.
보험 피싱 공격이 실시간 계정 탈취로 진화했다는 연구 결과.
Research reveals insurance phishing has evolved into real-time account hijacking.
블루노로프가 줌과 MS 팀을 사칭하여 암호화폐 지갑을 노리는 피싱 키트를 운영하고 있다.
BlueNoroff operates a phishing kit impersonating Zoom and MS Teams to target crypto wallets.
ChatGPT의 새로운 취약점이 발견되어 악성 AI 에이전트 배포가 가능하다고 경고했다.
A new vulnerability in ChatGPT could allow the deployment of rogue AI agents via a phishing link.
독일과 미국 법집행기관이 Kratos 피싱 키트를 해체했다.
German and US law enforcement dismantle Kratos phishing kit.
AI를 활용한 피싱 툴킷이 드러난 사건에 대한 분석.
AI-assisted phishing toolkit uncovered following exposed server incident.
OkoBot 악성코드 프레임워크가 Ledger와 Trezor 앱에 피싱 공격을 주입하고 있습니다.
The OkoBot malware framework injects phishing into Ledger and Trezor apps.
Forg365라는 새로운 피싱 서비스가 Microsoft 365를 겨냥하고 있습니다.
A new phishing service, Forg365, targets Microsoft 365 accounts.
잘못 구성된 서버가 Microsoft 365를 대상으로 한 피싱 공격 노출.
Misconfigured server reveals phishing operations targeting Microsoft 365.
해커들이 가짜 Microsoft Entra 패스키 등록 요청으로 Microsoft 365 접근을 시도합니다.
Hackers use fake Microsoft Entra passkey requests to gain access to Microsoft 365.
새로운 '유령 피싱' 기법이 전통적인 이메일 보안을 위협하고 있다.
A new ghost phishing technique threatens traditional email security.
M365 계정을 노리는 피싱 캠페인 발생, Microsoft 장치 로그인 방식 악용.
A phishing campaign targeting M365 accounts has been observed, abusing Microsoft's device login methods.
최근 연구에 따르면 피싱 훈련의 효과가 미미해 보인다.
Recent study suggests security training may have minimal impact on phishing prevention.
새로운 Avalan 악성코드 프레임워크가 CrownX 랜섬웨어 기능을 포함하고 있습니다.
The new Avalon malware framework includes capabilities for CrownX ransomware.
VEIL#DROP 공격 체인이 Blogger 플랫폼을 통해 PureLogs 훔치는 악성코드를 배포하는 사례로 주목받고 있다.
The VEIL#DROP attack chain uses Blogger to deliver the PureLogs info-stealer malware.
Ousaban 은행 트로잔이 스페인과 포르투갈 사용자들을 겨냥하고 있습니다.
Ousaban banking trojan targets Windows users banking in Spain and Portugal.
AI가 만들어낸 도메인을 악용한 피싱 공격이 증가하고 있다.
Phantom squatting uses AI-generated domains for phishing attacks.
236,000개의 DCloud Uni-App 사이트가 암호화폐 사기에 사용되고 있다.
Over 236,000 DCloud Uni-App sites are being used in crypto scams.
FBI와 CISA가 러시아 해커의 Signal 계정 타겟 경고를 업데이트했습니다.
FBI and CISA warn about Russian hackers targeting Signal accounts by stealing Backup Recovery Keys.
마이크로소프트는 ZIP 파일을 활용한 호텔 대상 피싱 캠페인을 경고했습니다.
Microsoft warns of a phishing campaign targeting hotels using ZIP files with a Node.js implant.
주간 보안 소식: 스마트 TV 프록시웨어 및 24년 된 curl 버그 발생.
Weekly security update: threats from smart TV proxyware and a 24-year-old curl bug.