Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack
ID: cf1233d6-541b-525b-bebe-00260ad82c0b
STIX ID: report--cf1233d6-541b-525b-bebe-00260ad82c0b
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 reports on a North Korean IT-worker cluster (CL-STA-0237) that used fake recruiter personas and malicious video-conference installers to deliver BeaverTail and InvisibleFerret malware, leveraged stolen or fabricated identities and Lao-based IPs, compromised SMB resources and obtained SSO access at a major tech company, and includes detailed IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
