DPRK Exploits 2 MITRE Sub-Techniques: Phantom DLL Hijacking, TCC Abuse
ID: a1164f4a-fbf0-557f-8f59-c0f5de0bedc1
STIX ID: report--a1164f4a-fbf0-557f-8f59-c0f5de0bedc1
Feed Name: Dark Reading
Dark Reading describes two sub-techniques MITRE will add to ATT&CK that North Korean APTs have exploited: manipulation of macOS Transparency, Consent, and Control (TCC) to grant permissions when System Integrity Protection or Full Disk Access are disabled, and "phantom" DLL hijacking on Windows where referenced-but-nonexistent DLLs are replaced with malicious ones. The article links these techniques to Lazarus Group, APT37/CloudMensis, and APT41, lists malware families abusing the flaws, and recommends preventive measures including keeping SIP enabled, auditing app permissions, deploying monitoring and application controls, and blocking remote DLL loading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
