logo

North Korean APT InkySquid Infects Victims Using Browser Exploits

ID: 5cd77db9-7663-5d0d-85fe-3ef1c0eeb358

STIX ID: report--5cd77db9-7663-5d0d-85fe-3ef1c0eeb358

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2021-08-17

Date Updated: 2026-05-01

...
...

Volexity investigated a strategic web compromise of the Daily NK site (Mar–Jun 2021) attributed to InkySquid (aka ScarCruft/APT37). Attackers injected conditional JavaScript into legitimate site assets to redirect Internet Explorer users to exploit pages leveraging CVE-2020-1380 and CVE-2021-26411, delivered Cobalt Strike stagers, and ultimately deployed a custom backdoor named BLUELIGHT that uses Microsoft Graph/OneDrive for C2 and data exfiltration; IoCs and signatures are published alongside the analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.