logo

North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics

ID: ea7c2eb8-832d-56e6-a999-4034cce098b8

STIX ID: report--ea7c2eb8-832d-56e6-a999-4034cce098b8

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-14

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Google/Mandiant/TAG and other researchers report that multiple North Korea-linked APTs have been actively targeting Brazil (and other regions) since 2020, accounting for roughly one-third of phishing against Brazil. Notable clusters—UNC4899 (trojanized Python app via GitHub), PAEKTUSAN (C++ downloader via Word attachments), PRONTO (credential-harvesting against diplomats), Moonstone Sleet and Kimsuky—use job-themed social engineering, malicious npm packages, and spoofed communications to distribute info-stealers, ransomware, and second-stage payloads against government, aerospace, fintech, crypto, and human-rights targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.