Sector A04
2020-03-12 • NSHC • HACKING ACTIVITY OF SECTORA GROUP IN 2019
SectorA04 is one of several hacking groups NSHC's ThreatRecon researchers track under the SectorA naming scheme in their monthly Threat Actor Group Intelligence Reports, with SectorA04-specific activity confirmed by NSHC as early as April 2021. The group's operations have targeted South Korea, including spear-phishing emails sent to government agencies and North Korea researchers using lures such as fake portal account-verification notices and monthly North Korea trend reports, and watering-hole attacks that injected malicious scripts into public-institution websites to infect visitors. It has also attacked manufacturing, media, construction, and educational organizations in South Korea using Word-based malware and files disguised as OpenVPN client installers to fetch staged payloads from command-and-control servers, and compromised corporate central-management software to distribute malware. Its activity has extended beyond Korea as well, including ransomware attacks against small businesses in Germany and Hungary, and a fake-recruiter campaign in Italy and Colombia that delivered malicious PDF readers capable of remote command execution, file downloads, and data theft.
-
19
Related Actors
-
162
Related Reports