#KittyPhishing
Incident/Operation
2019-01-30 • The Double Life of SectorA05 Nesting in Agora (Operation Kitty Phishing)
Operation KittyPhishing is a DPRK-linked campaign observed for at least 27 months by January 2019 and still showing related activity in April 2022. It targeted South Korean government, unification, diplomatic, defense, media, cryptocurrency, and individual users for intelligence collection and cryptocurrency theft. Operators combined credential phishing with malicious archives and Word documents, impersonated Korean security, internet, and cryptocurrency organizations, and used template injection to retrieve VBA downloaders; an early wave sent password-protected archives to 77 reporters and disguised an executable with a Hangul document icon.
-
2
Tagged Reports
-
2
Unique Authors
-
1,168
Active Days