« Reports in 2020 »

204 reports

2020-04-08 • Issuemakers Lab

IssueMakersLab described Operation Daily Coffee as daily spear phishing activity by North Korea's RGB-D5. The post says the group sends attacks to dozens or hundreds of South Korean key figures every day and presents the shared image as a small sample fro…

#Phishing #RGB-D5 #DailyCoffee
2020-03-31 • Igloo

IGLOO profiles Kimsuky as a suspected North Korean group focused on domestic Korean targets for information collection and social disruption, citing the 2014 KHNP incident and continued use of social-engineering themes tied to Korean and North Korea-relat…

#Kimsuky
2020-03-25 • NSFOCUS

NSFOCUS describes APT37 as a North Korea-linked actor whose delivery tradecraft is shaped by its focus on South Korea, defectors and political targets. The report details repeated use of spear-phishing with malicious Hangul Word Processor documents, inclu…

#APT37
2020-03-25 • NSFOCUS

NSFOCUS profiles APT37, also known as Group123, Venus 121 and Reaper, as a North Korea-linked actor active since 2012 and focused on neighboring countries, especially South Korea. The tool review highlights PoorWeb, RokRat, NavRat, KevDroid and PubNub, de…

#APT37