North Korean APT InkySquid Infects Victims Using Browser Exploits
ID: 5cd77db9-7663-5d0d-85fe-3ef1c0eeb358
STIX ID: report--5cd77db9-7663-5d0d-85fe-3ef1c0eeb358
Feed Name: Volexity Blog
Volexity investigated a strategic web compromise of the Daily NK site (Mar–Jun 2021) attributed to InkySquid (aka ScarCruft/APT37). Attackers injected conditional JavaScript into legitimate site assets to redirect Internet Explorer users to exploit pages leveraging CVE-2020-1380 and CVE-2021-26411, delivered Cobalt Strike stagers, and ultimately deployed a custom backdoor named BLUELIGHT that uses Microsoft Graph/OneDrive for C2 and data exfiltration; IoCs and signatures are published alongside the analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
