North Korea's Kimsuky Taps Trusted Platforms to Attack South Korea
ID: 6c966665-c144-53a7-ba0f-8742e31ed020
STIX ID: report--6c966665-c144-53a7-ba0f-8742e31ed020
Feed Name: Dark Reading
A North Korea-linked APT (Kimsuky) ran a DEEP#DRIVE phishing campaign that tricked targets into executing a zipped shortcut which collected system configuration data, uploaded it to Dropbox using OAuth-protected folders, and fetched additional PowerShell/.NET payloads; researchers observed signs of thousands of configuration files and evidence of lateral movement, indicating large-scale espionage-focused operations with improved OPSEC and some financial targeting of cryptocurrency users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
