UCID902
2023-04-12 • Inter Lab • UCID902: Uncovering nation state watering hole cr…
Interlab, a Seoul-based non-profit, has tracked UCID902 since 2021 as an advanced persistent threat cluster conducting watering-hole credential-harvesting campaigns against human rights activists and organizations advocating for North Korean human rights and Korean unification. The group compromises legitimate South Korean business and institutional websites, often ones built by a single shared web-development company, to host phishing pages that mimic Naver login pages, using lures disguised as Naver security alerts or official notifications; a validation check on the phishing kit redirects non-target visitors to the legitimate Naver site to reduce detection. Documented cases include phishing pages hosted on a law firm's website and on multiple medical research institution websites sharing common infrastructure. Interlab notes infrastructure and capability overlaps with the Kimsuky threat group, including a campaign using a malicious HWP document with lure themes referencing North Korea's Ministry of Unification, and states the group's motivations and targeting closely resemble those of North Korea-based threat actors, while cautioning that confidence in a specific North Korean attribution remains moderate given limited corroborating data points.
-
26
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster