Phishing Email Attacks by the Larva-24005 Group Targeting Japan
ID: 775c0a12-9843-5be5-8756-92e36d91f564
STIX ID: report--775c0a12-9843-5be5-8756-92e36d91f564
Feed Name: ASEC
AhnLab ASEC details Larva-24005 (a Kimsuky sub-group) conducting targeted phishing operations against organizations and researchers in South Korea and Japan: attackers gain initial access to poorly protected Windows systems (RDP brute force and BlueKeep/CVE-2019-0708 exploitation), install XAMPP/PHPMailer and a custom keylogger, host bespoke phishing pages to harvest credentials (Zoom/Microsoft/iCloud/OneDrive/etc.), and use stolen or attacker-created mail accounts to send spear-phishing; the report provides related IOCs (email addresses, URLs, MD5) and guidance to verify senders and URLs before entering credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
