#CloudDragon

Incident/Operation

2021-05-07 • “We are about to land.” : How CloudDragon Turns a Nightmare into Reality

CloudDragon is a subgroup of the North Korean Kimsuky threat cluster that conducts cyberespionage and some financially motivated activity. It has primarily targeted South Korean government, policy, aerospace, and other strategic organizations through tailored phishing, credential-harvesting infrastructure, and exploitation of VPN vulnerabilities. Its tooling includes BabyShark, AppleSeed-related malware, and MemzipRAT. CloudDragon also operates phishing systems for bulk message delivery, cloned login pages, mobile-aware redirection, and proxy-mirror techniques that capture credentials while preserving the appearance of legitimate services.

Tagged Reports

« Back