North Korean government hackers target individuals of interest, infosec professionals
ID: 3223a686-56c7-5ea6-bded-1c01e79daf0c
STIX ID: report--3223a686-56c7-5ea6-bded-1c01e79daf0c
Feed Name: CyberScoop
SentinelLabs observed North Korean APT ScarCruft (linked to the Ministry of State Security) conducting phishing campaigns in Nov–Dec 2023 that targeted media organizations and high-profile experts and prepared a likely campaign aimed at cybersecurity researchers; victims who executed the phishing were targeted with the RokRAT backdoor, and researchers recovered planning/testing-phase malware using decoy technical reports, indicating continued strategic-intelligence collection and intent to target cyber defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
