DPRK, China Suspected in South Korean Embassy Attacks
ID: b989fa87-319f-5e5c-aea4-55516bd595eb
STIX ID: report--b989fa87-319f-5e5c-aea4-55516bd595eb
Feed Name: Dark Reading
Since March, a campaign resembling North Korea's Kimsuky has targeted European diplomatic missions in Seoul with highly personalized spear-phishing messages containing password-protected PDFs; successful clicks execute PowerShell that gathers system telemetry and uses GitHub-hosted files for command-and-control to deliver an obfuscated XenoRAT. Rapid, frequent modifications to C2 artifacts and observed operator work hours aligning with China suggest either routing through Chinese infrastructure or collaboration, increasing operational stealth and complicating detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
