North Korea-Linked Group Levels Multistage Cyberattack on South Korea
ID: 22e532dd-81c8-582a-9e16-e2958e10ef60
STIX ID: report--22e532dd-81c8-582a-9e16-e2958e10ef60
Feed Name: Dark Reading
North Korea-linked APT Kimsuky (DEEP#GOSU) ran an eight-stage campaign against South Korean targets using LNK email attachments that pull PowerShell/VBScript from Dropbox/Google, install .NET components and the TutClient RAT, and ultimately deploy persistence and keylogging; the operators rely on living-off-the-land techniques, AES-encrypted stages, and legitimate cloud services to blend traffic and evade detection while pursuing cyber espionage and cryptocurrency-focused financial crime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
