North Korean APT Bypasses DMARC Email Policies in Cyber-Espionage Attacks
ID: 2632e437-d7b5-55a6-a855-2f526d93a39e
STIX ID: report--2632e437-d7b5-55a6-a855-2f526d93a39e
Feed Name: Dark Reading
Threat Score
Kimsuky, a North Korean APT tied to the Reconnaissance General Bureau, is conducting spear-phishing campaigns that exploit missing or misconfigured DMARC policies to spoof legitimate domains and impersonate trusted organizations (think tanks, media, academia, and government) to gather geopolitical intelligence; US agencies have issued advisories and the report emphasizes that proper DMARC configuration and stronger email hygiene are key mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
