TA404

2022-07-14 • ProofpointAbove the Fold and in Your Inbox: Tracing State-A…

Proofpoint, in a July 2022 report on state-aligned activity targeting journalists and media, described the North Korea-aligned actor TA404, known more broadly by researchers as Lazarus, targeting a US-based media organization in early 2022 with job-opportunity-themed phishing shortly after that organization published an article critical of North Korean leader Kim Jong Un. Consistent with TA404's typical pattern of beginning campaigns with benign reconnaissance before sending malware, the operation used recipient-customized URLs that impersonated a branded job-posting landing page; interacting with the link, which contained a unique target identifier, confirmed the email had been delivered and opened, and also collected identifying information about the victim's device. Proofpoint did not observe a follow-on malicious attachment in this instance but assessed one was likely, based on the actor's established behavior. Proofpoint also noted that Google's Threat Analysis Group disclosed related activity on March 24, 2022 as part of "Operation Dream Job," sharing overlapping indicators of compromise with the campaigns Proofpoint tracked, though journalism and media were not listed among the targeted sectors in Google's disclosure.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster