DPRK hacking groups breach South Korean defense contractors
ID: b9cf3483-e561-5146-9f54-bf30b92dd541
STIX ID: report--b9cf3483-e561-5146-9f54-bf30b92dd541
Feed Name: Bleeping Computer
South Korean police warned that North Korean hacking groups Lazarus, Andariel, and Kimsuky successfully breached multiple defense contractors and subcontractors (compromises dating back to late 2022) by exploiting vulnerable systems, stolen credentials, and an email-server flaw, installing malware to exfiltrate substantial defense-related technical data; authorities conducted inspections and recommended network segmentation, multifactor authentication, password hygiene, and blocking foreign IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
