AhnLab linked an election-period malicious document campaign to Kimsuky, centered on Word documents that contacted saemaeul.mireene[.]com infrastructure previously associated with the group. The initial document contained election-related content but did …
« Reports in 2020 »
204 reports
ESRC reported another Kimsuky “Smoke Screen” campaign using malicious DOCX files disguised as South Korean National Assembly election and diplomacy-related documents. The documents referenced an external template at saemaeul.mireene[.]com in settings.xml.…
McAfee found a new MalBus Android variant inserted into a South Korean education app distributed through ONE Store after earlier MalBus activity had used Google Play. The malicious versions loaded an encrypted native payload after a 10-hour delay to evade…
IssueMakersLab described Operation Daily Coffee as daily spear phishing activity by North Korea's RGB-D5. The post says the group sends attacks to dozens or hundreds of South Korean key figures every day and presents the shared image as a small sample fro…
AhnLab's Operation Ghost Union report profiles Kimsuky activity against South Korean institutions and companies. The report says Kimsuky, active since at least 2013, has expanded targeting from military-related areas into political, economic, and social s…
The Dangerous Password analysis describes a malicious self-extracting RAR and LNK chain that launches mshta through a Bitly redirect to attacker-controlled infrastructure. The HTA displays a decoy password file while installing persistence through a start…
ASEC reported malicious HWP documents disguised as urgent COVID-19 response inquiries from Korean regional infection-control organizations, including Jeollanam-do and Incheon. Unlike common Office macro lures, these Hangul files embedded EPS content that …
IGLOO profiles Kimsuky as a suspected North Korean group focused on domestic Korean targets for information collection and social disruption, citing the 2014 KHNP incident and continued use of social-engineering themes tied to Korean and North Korea-relat…
ESRC attributed Operation Spy Cloud to the Geumseong121 APT group after observing spear-phishing emails that lured South Korean targets with fake evidence of North Korean defection. The emails linked to downloadable archives containing a malicious Word do…
NSFOCUS describes APT37 as a North Korea-linked actor whose delivery tradecraft is shaped by its focus on South Korea, defectors and political targets. The report details repeated use of spear-phishing with malicious Hangul Word Processor documents, inclu…
NSFOCUS profiles APT37, also known as Group123, Venus 121 and Reaper, as a North Korea-linked actor active since 2012 and focused on neighboring countries, especially South Korea. The tool review highlights PoorWeb, RokRat, NavRat, KevDroid and PubNub, de…
ESRC reports that Kimsuky reused COVID-19 themes in a Smoke Screen-linked spear-phishing campaign distributing a Word document named “COVID-19 and North Korea.docx.” When macros are enabled, the document contacts attacker-controlled C2 and uses PowerShell…
StrangerealIntel analyzes a Kimsuky intrusion chain that begins with a malicious Office document using remote template injection to fetch a second-stage macro from crphone.mireene.com. On macOS, the macro uses Office's bundled Python 2.7 support to execut…
NSHC’s 2019 SectorA overview tracks North Korea-linked subgroups, with SectorA01, SectorA02 and SectorA05 the most active in the excerpted period. SectorA01 focused on financially motivated intrusions against banks, ATMs, cryptocurrency exchanges and targ…