North Korea APT Triumvirate Spied on South Korean Defense Industry For Years
ID: bd3cd656-9dc1-51c1-a01e-340d581d49ca
STIX ID: report--bd3cd656-9dc1-51c1-a01e-340d581d49ca
Feed Name: Dark Reading
South Korean police disclosed concurrent espionage campaigns by DPRK-linked APTs Andariel, Kimsuky, and the broader Lazarus Group that infiltrated roughly 10 defense-related organizations over at least 18 months, using credential compromise, exploitation of a groupware/email vulnerability, and deployment of RATs (Nukesped, Tiger) to harvest and exfiltrate defense-related data; investigators tied malware and infrastructure (including some IPs) to prior attacks and recommended two-factor authentication, network segmentation, password rotation, and blocking unauthorized foreign IP addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
