#CloudDragon
Incident/Operation
2021-05-07 • “We are about to land.” : How CloudDragon Turns a Nightmare into Reality
CloudDragon is a subgroup of the North Korean Kimsuky threat cluster that conducts cyberespionage and some financially motivated activity. It has primarily targeted South Korean government, policy, aerospace, and other strategic organizations through tailored phishing, credential-harvesting infrastructure, and exploitation of VPN vulnerabilities. Its tooling includes BabyShark, AppleSeed-related malware, and MemzipRAT. CloudDragon also operates phishing systems for bulk message delivery, cloned login pages, mobile-aware redirection, and proxy-mirror techniques that capture credentials while preserving the appearance of legitimate services.
-
7
Tagged Reports
-
2
Unique Authors
-
736
Active Days
Tagged Reports
2021-05-21
Macnica