Sector A
2019-01-10 • NSHC • MONTHLY THREAT ACTOR GROUPS INTELLIGENCE REPORT, …
SectorA is NSHC Security’s umbrella designation for a collection of North Korean threat-actor subgroups pursuing state intelligence and foreign-currency objectives. NSHC’s 2019 activity review described at least seven subgroups, with SectorA01, SectorA02, and SectorA05 particularly active and SectorA06 and SectorA07 emerging in specific periods. Their targets included government ministries, public enterprises, political and diplomatic organizations, defectors and support groups, banks, cryptocurrency exchanges and holders, defense and military-related entities, and companies across Asia, Europe, the Middle East, Africa, and the Americas. SectorA campaigns commonly used spear-phishing with malicious Hangul, Word, Excel, script, executable, or multimedia files, supplemented by social engineering, credential phishing, watering holes, and vulnerability exploitation. Individual subgroups divided responsibilities between financial theft and collection of political, diplomatic, military, and strategic information, while adjusting malware and lure formats to target regions and sectors.
-
16
Related Actors
-
147
Related Reports