Sector A05
2019-01-10 • NSHC • HACKING ACTIVITY OF SECTORA GROUP IN 2019
NSHC's ThreatRecon team tracks SectorA05 as one of several hacking groups operating under its broader SectorA grouping, consistently linked to politically motivated hacking against South Korea alongside financially motivated cryptocurrency theft intended to offset international sanctions. In a campaign NSHC named Operation Kitty Phishing, SectorA05 sent malware-laden, password-protected archives disguised as Hangul Word Processor documents to South Korean reporters covering Unification Ministry topics in January 2019, deploying parallel DLL-based and script-based remote access tools alongside long-running email credential-phishing operations targeting South Korean government, diplomatic, and defense personnel and Gmail users. The group used Google Drive to stage malware and configuration data and maintained a compromised Korean-domain command-and-control server continuously for more than 27 months. NSHC observed SectorA05 increasingly pivoting toward stealing cryptocurrency wallets and private keys from exchange employees, individual traders, and developers alongside its traditional espionage targeting, reflecting a dual mandate of intelligence collection and sanctions-evasion revenue generation.
-
43
Related Actors
-
58
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster