logo

North Korean APT Bypasses DMARC Email Policies in Cyber-Espionage Attacks

ID: 2632e437-d7b5-55a6-a855-2f526d93a39e

STIX ID: report--2632e437-d7b5-55a6-a855-2f526d93a39e

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-20

Date Updated: 2026-04-21

Author: Dr. Sean Costigan

...
...

Kimsuky, a North Korean APT tied to the Reconnaissance General Bureau, is conducting spear-phishing campaigns that exploit missing or misconfigured DMARC policies to spoof legitimate domains and impersonate trusted organizations (think tanks, media, academia, and government) to gather geopolitical intelligence; US agencies have issued advisories and the report emphasizes that proper DMARC configuration and stronger email hygiene are key mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.