TA406

2021-11-19 • ProofpointTriple Threat: North Korea-Aligned TA406 Scams, S…

Proofpoint tracks TA406 as a North Korea-aligned threat actor and one of several distinct actors that make up activity publicly tracked by others as Kimsuky, Thallium, and Konni Group; Proofpoint separately distinguishes TA406 from two related actors it designates TA408 and TA427. Proofpoint observed TA406 campaigns targeting its customers since 2018, with volume remaining low until activity increased sharply from January through June 2021, when the group conducted almost weekly credential-theft campaigns against foreign policy experts, journalists, and non-governmental organizations, alongside research, education, government, and media organizations more broadly. TA406 primarily relies on credential-harvesting phishing rather than malware, though two notable 2021 campaigns attempted to distribute previously undocumented implants for information gathering. Beyond espionage, the group engages in financially motivated activity, including cryptocurrency-focused campaigns and sextortion schemes, reflecting a threat actor that blends state-aligned intelligence collection with opportunistic criminal monetization.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster