logo

NSA warns of North Korean hackers exploiting weak DMARC email policies

ID: da129b98-e1cd-5c13-b1bd-c8fab4b5be96

STIX ID: report--da129b98-e1cd-5c13-b1bd-c8fab4b5be96

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-03

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

NSA, FBI, and the U.S. State Department warn that the North Korea-linked APT43 (aka Kimsuky) exploits missing or 'p=none' DMARC policies to deliver spearphishing emails that impersonate journalists and academics, targeting think tanks, research centers, academic institutions, and media across the United States, Europe, Japan, and South Korea; the advisory recommends updating DMARC to 'quarantine' or 'reject' and enabling reporting (rua) to mitigate this espionage-focused campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.