logo

North Korean Hackers Exploit Facebook Messenger in Targeted Malware Campaign

ID: ffbc93cc-9ee8-5206-865d-0e63aa390111

STIX ID: report--ffbc93cc-9ee8-5206-865d-0e63aa390111

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-16

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Genians attributes a multi-stage social-engineering campaign to the North Korea-linked Kimsuky group that uses fictitious Facebook personas and Facebook Messenger to trick targets into opening MSC files disguised as benign Word documents. When launched via Microsoft Management Console (MMC) the MSC triggers commands to contact a C2 domain (brandwizer.co.in), display decoy documents hosted on cloud services, establish persistence, collect system/process/battery and network metadata, and exfiltrate that information; the campaign appears focused on North Korean human-rights and anti-North Korea activists in South Korea and Japan and reuses TTPs seen in prior ReconShark activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.