#FakeStriker

Incident/Operation

2019-05-20 • 김수키 조직, 한국을 겨냥한 '페이크 스트라이커' APT 작전 개시

FakeStriker is a North Korea-linked espionage campaign targeting South Korean officials, diplomats, defense and unification specialists, academics, journalists, human-rights organizations, and other North Korea-focused communities. Active from at least 2019, it impersonates trusted institutions or contacts in tailored emails and credential-phishing pages, then delivers malicious HWP, Word, or PDF documents that exploit vulnerabilities or execute macros and scripts to install payloads, steal information, and enable remote control. The activity has been attributed to Kimsuky/Thallium with assessed, rather than absolute, confidence, based on recurring infrastructure, communications patterns, hosting, and attack techniques.

Tagged Reports

« Back