#FracturedStatue

Incident/Operation

2020-01-23 • The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks

Fractured Statue was a spear-phishing campaign observed from July through October 2019, primarily targeting a United States government agency and two foreign nationals professionally connected to North Korea. The lures used Russian-language geopolitical material about North Korea and were sent as malicious Word attachments to ten targets. Five documents carried CARROTBAT downloaders and one introduced the CARROTBALL FTP downloader; every observed second-stage payload was the SYSCON remote-access trojan. The malware set and delivery patterns were typically associated with the Konni Group, though the campaign represented an evolution in that actor’s tradecraft.

Tagged Reports

« Back