TA427

2021-11-19 • ProofpointTriple Threat: North Korea-Aligned TA406 Scams, S…

TA427 is one of three distinct threat-actor clusters, alongside TA406 and TA408, that Proofpoint separates out of the broader activity publicly known as Kimsuky; Proofpoint also refers to TA427 as Emerald Sleet, APT43, THALLIUM, or Kimsuky, and assesses it as a DPRK-aligned group working in support of the Reconnaissance General Bureau. TA427 conducts long-running social-engineering campaigns against foreign-policy experts, journalists, academics, and think-tank or NGO-affiliated individuals in the United States and South Korea, using benign 'conversation starter' emails about nuclear disarmament, sanctions, and bilateral policy to build rapport over weeks or months before seeking sensitive analysis or opinions; malware or credential harvesting is used only rarely, after extended engagement. Since 2023 the group has impersonated well-known think tanks, and since December 2023 has abused permissive email-authentication policies, typosquatted domains, and private-email spoofing to pose as these personas, later adding hidden tracking images in February 2024 for reconnaissance of target email activity.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster