Sector A01

2019-01-23 • NSHCSectorA01 Custom Proxy Utility Tool Analysis

SectorA01 is a designation used by South Korean firm NSHC's ThreatRecon team, appearing as early as a January 2019 report analyzing a custom proxy utility tied to the group's activity against financial-sector targets worldwide. NSHC has tracked SectorA01 as one of several numbered "SectorA" subgroups that collectively pursue South Korean government and diplomatic, financial, and research-sector targets worldwide, chiefly via spear-phishing links, alongside exploitation of software vulnerabilities, including a 2023 3CX supply-chain compromise, and abuse of legitimate cloud services such as OneDrive for command-and-control. A November 2025 NSHC report, identifying SectorA01 as also known as Lazarus, details a May 2025 campaign against cryptocurrency users in which a fake Deriv trading-app installer launched a multi-stage, multi-language infection chain, an Electron/JavaScript stage mimicking the real Deriv site while covertly beaconing to an attacker server, a Python stage, and a final backdoor, that stole browser credentials, wallet files, and clipboard data, logged keystrokes, deployed AnyDesk for hands-on control, and used Tor-based command-and-control with defense-evasion tampering.

Related Actors

Related Reports in This Cluster

Top Authors

View Sector A01 reports only

View Sector A01 reports only