North Korean Hackers Exploit Facebook Messenger in Targeted Malware Campaign
ID: ffbc93cc-9ee8-5206-865d-0e63aa390111
STIX ID: report--ffbc93cc-9ee8-5206-865d-0e63aa390111
Feed Name: The Hacker News
Genians attributes a multi-stage social-engineering campaign to the North Korea-linked Kimsuky group that uses fictitious Facebook personas and Facebook Messenger to trick targets into opening MSC files disguised as benign Word documents. When launched via Microsoft Management Console (MMC) the MSC triggers commands to contact a C2 domain (brandwizer.co.in), display decoy documents hosted on cloud services, establish persistence, collect system/process/battery and network metadata, and exfiltrate that information; the campaign appears focused on North Korean human-rights and anti-North Korea activists in South Korea and Japan and reuses TTPs seen in prior ReconShark activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
