Threats Tagged 'blindingcan - s0520'
View all threats tagged with 'blindingcan - s0520'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'blindingcan - s0520'
Click on any threat for detailed analysis and mitigation recommendations
North Korean threat actors Kimsuky and Lazarus have deployed new sophisticated malware toolsets named HttpTroy and an upgraded BLINDINGCAN variant. HttpTroy is a backdoor delivered via a VPN invoice-themed attack, involving a dropper and loader (MemLoad), granting extensive system control. Lazarus's upgraded BLINDINGCAN is delivered through a new Comebacker malware variant, targeting victims in Canada. Both toolsets use advanced obfuscation, stealth techniques, and layered evasion to avoid detection. These attacks highlight DPRK's evolving cyber espionage capabilities. Although currently observed targeting South Korea and Canada, European organizations could be at risk due to geopolitical tensions and similar attack methodologies. No known exploits in the wild have been reported yet. Mitigation requires targeted detection of these toolsets, network monitoring for associated indicators, and enhanced endpoint defenses. The threat is assessed as medium severity due to its espionage focus, stealth, and complexity, but limited current scope and no public CVSS score. Join the discussion | AlienVault OTX General | 11/03/2025, 10:19:23 UTC Added: 11/03/2025, 10:56:13 UTC |
Showing 1 to 1 of 1 result