North Korean state-sponsored hacker group APT37 has conducted a spear phishing campaign targeted at North Korean activists. Disguised as academic invitations from a South Korean think-tank, the emails contain Dropbox links that direct victims to download malware-infected compressed archives. Genians Security Center analyzed this sophisticated cyber attack, dubbed “Operation: ToyBox Story.” The ongoing use of Airbnb for command and control infrastructure is making differentiation between malicious and legitimate traffic increasingly difficult.

Software Exploit Breach Affects Nearly 440,000
Ascension Health, a Missouri-based hospital chain, reported a data breach affecting around 440,000 patients due to a vulnerability in a third-party software used by a