logo

North Korean hackers linked to defense sector supply-chain attack

ID: 6e41823e-ee2f-5741-8d88-aa98e27d2549

STIX ID: report--6e41823e-ee2f-5741-8d88-aa98e27d2549

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Germany's BfV and South Korea's NIS warn of active North Korean cyber‑espionage against the global defense sector, detailing a 2022 supply‑chain compromise of a web‑server maintenance provider that enabled SSH credential theft, lateral movement, web shells and attempted malicious patch distribution, plus social‑engineering campaigns (Operation Dream Job) used to deliver backdoors like LightlessCan; the advisory lists TTPs and recommends limiting third‑party access, enforcing MFA and least privilege, hardening patch management, monitoring logs, and employee training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.