Nickel Foxcroft
2023-05-28 • Secure Works • NICKEL FOXCROFT
Secureworks Counter Threat Unit researchers track NICKEL FOXCROFT as a targeted threat group they assess with moderate confidence conducts cyberespionage on behalf of the North Korean government. Its targeting is concentrated almost exclusively on South Korea, focusing on individuals and organizations involved in reporting on North Korea, researching Korean-peninsula geopolitics, or supporting North Korean defectors. Consistent with other North Korean-linked groups, NICKEL FOXCROFT relies heavily on social engineering and spearphishing to gain initial access; in at least one instance the group socially engineered victims into surrendering social media credentials, then used that access to more effectively target the victims' associates. Historically the group exploited vulnerabilities in Hangul Word Processor files, a format widely used by South Korean public and private organizations, before shifting to malicious Microsoft Word documents delivered via spearphishing email. These documents deploy tooling that provides credential theft, data exfiltration, screenshot capture, system information collection, and file and directory management capabilities.
-
26
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster