North Korea ramps up cyberspying in Ukraine to assess war risk
ID: da69d159-cb61-54d2-b2eb-8bfdbc8c0270
STIX ID: report--da69d159-cb61-54d2-b2eb-8bfdbc8c0270
Feed Name: Bleeping Computer
Proofpoint observed North Korea–linked Konni (TA406) conducting targeted phishing campaigns against Ukrainian government entities to collect intelligence related to DPRK involvement and battlefield conditions; attackers use convincing think-tank lures and fake Microsoft alerts to deliver MEGA-hosted RAR/CHM archives or ZIP/LNK attachments that execute encoded PowerShell/VBScript and attempt persistence and credential harvesting, while the final espionage payload was not recovered but is assessed to be a backdoor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
