#DeepDrive
Incident/Operation
2025-02-13 • Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks
DEEP#DRIVE is an ongoing Kimsuky campaign targeting South Korean businesses, government organizations, and cryptocurrency users. The operators used tailored Korean-language phishing lures disguised as work logs, insurance records, and cryptocurrency documents in trusted formats, while Dropbox hosted payloads and received stolen system information. The multistage chain relied heavily on obfuscated PowerShell for delivery, reconnaissance, and execution, established persistence through scheduled tasks, and used short-lived infrastructure and trusted cloud services to blend malicious activity into normal user behavior.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days