logo

DPRK's Kimsuky APT Abuses Weak DMARC Policies, Feds Warn

ID: cae1ad9c-970c-515a-8fba-7ceed6629154

STIX ID: report--cae1ad9c-970c-515a-8fba-7ceed6629154

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-02

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

North Korean APT Kimsuky is exploiting weak or nonexistent DMARC configurations to send convincing, targeted spear-phishing emails that impersonate trusted organizations and target journalists, think tanks, and government-affiliated individuals; the FBI and NSA recommend enforcing DMARC with p=reject or p=quarantine and maintaining SPF/DKIM hygiene to reduce spoofing risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.