logo

Microsoft shares latest intelligence on North Korean and Chinese threat actors at CYBERWARCON

ID: 1661b2f7-9687-5d3b-819a-1b6d280e6148

STIX ID: report--1661b2f7-9687-5d3b-819a-1b6d280e6148

Feed Name: Microsoft Security

Threat Score
88/100

Date Published: 2024-11-22

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence summarizes research presented at CYBERWARCON on nation-state activity: North Korean groups (Sapphire Sleet and Ruby Sleet) have conducted social-engineering-driven cryptocurrency theft, supply-chain compromises (including a backdoored VeraPort), distribution of backdoored VPNs and signed malware, and have used an organized network of remote IT workers to generate revenue and potentially access intellectual property; a China-aligned actor tracked as Storm-2077 conducts broad intelligence collection via phishing, credential harvesting, exploitation of edge devices, and cloud/email exfiltration across government, DIB, aviation, telecoms, and legal/financial sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.