Targeted APT Activity: BABYSHARK Is Out for Blood | Huntress
ID: d8a8a73f-98a9-5e7c-84d9-c527f1323d3c
STIX ID: report--d8a8a73f-98a9-5e7c-84d9-c527f1323d3c
Feed Name: Huntress Blog
This Huntress investigation describes a targeted DPRK-linked APT (BABYSHARK) campaign against a nuclear think tank: initial access was gained via a password-protected Word document with malicious macros, followed by VBScript-based staged payloads fetched from Google Drive/OneDrive, scheduled-task and registry persistence, a DLL-hijack to load a RAT (likely KimJongRAT), and periodic data collection/exfiltration to multiple C2 domains; the report includes detailed technical analysis, timelines, and a comprehensive IOC table.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
