North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics
ID: ea7c2eb8-832d-56e6-a999-4034cce098b8
STIX ID: report--ea7c2eb8-832d-56e6-a999-4034cce098b8
Feed Name: The Hacker News
Google/Mandiant/TAG and other researchers report that multiple North Korea-linked APTs have been actively targeting Brazil (and other regions) since 2020, accounting for roughly one-third of phishing against Brazil. Notable clusters—UNC4899 (trojanized Python app via GitHub), PAEKTUSAN (C++ downloader via Word attachments), PRONTO (credential-harvesting against diplomats), Moonstone Sleet and Kimsuky—use job-themed social engineering, malicious npm packages, and spoofed communications to distribute info-stealers, ransomware, and second-stage payloads against government, aerospace, fintech, crypto, and human-rights targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
