#FakeStriker
Incident/Operation
FakeStriker is a North Korea-linked espionage campaign targeting South Korean officials, diplomats, defense and unification specialists, academics, journalists, human-rights organizations, and other North Korea-focused communities. Active from at least 2019, it impersonates trusted institutions or contacts in tailored emails and credential-phishing pages, then delivers malicious HWP, Word, or PDF documents that exploit vulnerabilities or execute macros and scripts to install payloads, steal information, and enable remote control. The activity has been attributed to Kimsuky/Thallium with assessed, rather than absolute, confidence, based on recurring infrastructure, communications patterns, hosting, and attack techniques.
-
4
Tagged Reports
-
1
Unique Authors
-
1,242
Active Days