North Korean hackers exploit VPN update flaw to install malware
ID: e695489b-f135-5985-8fe5-afb6ed5681cc
STIX ID: report--e695489b-f135-5985-8fe5-afb6ed5681cc
Feed Name: Bleeping Computer
South Korea's National Cyber Security Center (NCSC) warns that DPRK state-backed groups Kimsuky and Andariel conducted supply-chain attacks in 2024: Kimsuky served trojanized, digitally signed installers from a compromised trade organization site to steal credentials, certificates, and files, while Andariel exploited a VPN update protocol vulnerability to push DoraRAT updates configured to exfiltrate large engineering and equipment design documents; the advisory identifies targeted sectors (construction, machinery, public institutions) and provides mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
