RST TI Report Digest: 17 Feb 2025
ID: 9ede7e49-90c4-57e6-8577-975847a5061d
STIX ID: report--9ede7e49-90c4-57e6-8577-975847a5061d
Feed Name: RST Cloud Blog
Threat Score
PurpleBravo, a North Korea–linked threat actor, targeted cryptocurrency firms and other organizations using fraudulent remote IT personnel, at least seven China-based front companies, and malware families (BeaverTail, InvisibleFerret, OtterCookie) to enable fraud, data theft, and persistent access; a January 2025 U.S. DOJ indictment alleges they targeted over 64 U.S. companies and includes multiple IOCs (IPs, domains, URLs, hashes, emails).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
