Winnti’s new UNAPIMON tool hides malware from security software

April 2, 2024 at 06:01PM The Chinese ‘Winnti’ hacking group used a new malware, UNAPIMON, to run malicious processes undetected. This group, active since 2012, targets various organizations and was linked to a cyberespionage attack named ‘Earth Freybug.’ UNAPIMON uses DLL side-loading and unhooking API functions to evade detection, showcasing innovative and sophisticated tactics by … Read more

macOS Malware Mix & Match: North Korean APTs Stir Up Fresh Attacks

November 28, 2023 at 12:43PM North Korean APT groups are using a mix of malware components from KandyKorn and RustBucket to avoid detection and continue their operations. They are targeting macOS machines to attack cryptocurrency exchanges and raise money for the Kim Jong Un regime. The groups are taking evasive steps by mixing loaders and … Read more