logo

Active North Korean campaign targeting security researchers

ID: f7570c5a-618f-592c-b1ce-86e2ccce9798

STIX ID: report--f7570c5a-618f-592c-b1ce-86e2ccce9798

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
70/100

Date Published: 2023-09-07

Date Updated: 2026-04-27

Author: Clement Lecigne

...
...

The report details a GitHub-published Windows utility intended to fetch debugging symbols for reverse engineers that contains hidden functionality to download and execute arbitrary code from attacker-controlled domains; the tool was published on September 30, 2022 and has been updated since. The activity is linked to targeting researchers with 0-day exploits, and the advisory recommends treating systems that ran the tool as compromised and performing OS reinstalls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.