PRONTO

2024-06-12 • GoogleInsights on Cyber Threats Targeting Users and Ent…

Google's Threat Analysis Group identifies Pronto as a North Korean government-backed group that concentrates on targeting diplomats globally, with observed activity against diplomatic targets in Brazil consistent with this broader pattern. In one documented case, Google blocked a Pronto campaign that used a denuclearization-themed phishing lure paired with the group's typical phishing kit, a fake PDF viewer that presents victims with a login prompt before allowing them to view the lure document, thereby harvesting their credentials. In a separate case, Pronto used lures themed around North Korea news coverage to direct diplomatic targets to credential-harvesting pages. This activity forms part of a broader pattern of North Korean government-backed cyber espionage against diplomatic, government, technology, aerospace, and financial targets in Brazil, alongside other North Korean groups observed pursuing cryptocurrency theft and job-themed social engineering in the region.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster