Thallium
2019-12-30 • Microsoft • Microsoft takes court action against fourth natio…
Thallium is Microsoft’s former designation for a threat group believed to operate from North Korea. Microsoft publicly named the actor in December 2019 while announcing legal action that enabled the company to seize fifty domains used in its operations. Thallium targeted government employees, think tanks, university personnel, peace and human-rights organizations, and specialists working on nuclear-proliferation issues, primarily in the United States, Japan, and South Korea. The group researched individuals through social media and public directories, then sent personalized spear-phishing messages that redirected victims to credential-harvesting sites. After compromising accounts, operators searched email, contacts, and calendars and created forwarding rules to retain access to new messages even after password changes. Thallium also deployed malware including BabyShark and KimJongRAT to steal information, establish persistence, and receive further commands, combining account compromise with endpoint intrusion for sustained intelligence collection.
-
43
Related Actors
-
799
Related Reports