2023 Activities Summary of SectorA groups (JPN)

2024-07-29 NSHC

https://redalert.nshc.net/2024/07/29/2023-activities-summary-of-sectora-groups-jpn/

Thumbnail for 2023 Activities Summary of SectorA groups (JPN)

NSHC's 2023 SectorA activity summary says seven SectorA subgroups ran both South Korea-focused intelligence collection and financially motivated operations worldwide. SectorA05 was the most active subgroup, followed by SectorA02 and SectorA01, with financial institutions, research organizations, and government agencies among the most frequent targets. Spear-phishing links were the most common initial access method, used to harvest credentials or persuade targets to execute malware. The excerpt also highlights exploitation of CVE-2023-29059 in 3CX DesktopApp and abuse of OneDrive as command-and-control-like infrastructure for downloading and running additional malware.

Related Actors

Related Reports

« Back