Skip to main content

Threats Tagged 'comebacker'

View all threats tagged with 'comebacker'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: comebacker

Threats Tagged 'comebacker'

Click on any threat for detailed analysis and mitigation recommendations

North Korean state-backed attackers are utilizing Medusa ransomware in their ongoing extortion attacks against the U.S.healthcare sector. The Symantec and Carbon Black Threat Hunter Team discovered evidence of North Korean actors employing Medusa in an attack on a Middle Eastern target and an unsuccessful attempt on a U.S.healthcare organization. Medusa, launched in 2023, operates as a ransomware-as-a-service. The Lazarus sub-group Stonefly has been a key player in North Korean ransomware attacks, using proceeds to fund espionage activities. Despite indictments and rewards, the attacks continue unabated. The current campaign employs various tools, including Comebacker, Blindingcan, ChromeStealer, and RP_Proxy. While the attacks bear similarities to previous Stonefly operations, the exact sub-group responsible remains unclear.

Join the discussion

The Lazarus Group, a DPRK-linked threat actor, has launched a targeted espionage campaign against aerospace and defense sectors using a new variant of the Comebacker backdoor. The attack employs spear phishing with highly specific lure documents to deliver macro-based malware. The infection chain is multi-staged, featuring custom decryption algorithms and encrypted command-and-control communications, indicating advanced evasion techniques. The campaign infrastructure remains active, suggesting ongoing operations. This threat poses risks to confidentiality and integrity of sensitive defense-related information. European aerospace and defense organizations should enhance phishing defenses and monitor for indicators such as specific file hashes and suspicious domains. No CVSS score is assigned, but the threat is assessed as high severity due to its targeted nature, potential impact, and sophisticated malware. Countries with significant aerospace and defense industries and geopolitical interest in DPRK activities are most at risk. Immediate mitigation includes user training, macro restrictions, network monitoring, and threat intelligence sharing.

Join the discussion

North Korean threat actors Kimsuky and Lazarus have deployed new sophisticated malware toolsets named HttpTroy and an upgraded BLINDINGCAN variant. HttpTroy is a backdoor delivered via a VPN invoice-themed attack, involving a dropper and loader (MemLoad), granting extensive system control. Lazarus's upgraded BLINDINGCAN is delivered through a new Comebacker malware variant, targeting victims in Canada. Both toolsets use advanced obfuscation, stealth techniques, and layered evasion to avoid detection. These attacks highlight DPRK's evolving cyber espionage capabilities. Although currently observed targeting South Korea and Canada, European organizations could be at risk due to geopolitical tensions and similar attack methodologies. No known exploits in the wild have been reported yet. Mitigation requires targeted detection of these toolsets, network monitoring for associated indicators, and enhanced endpoint defenses. The threat is assessed as medium severity due to its espionage focus, stealth, and complexity, but limited current scope and no public CVSS score.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: comebacker
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses