2024 Activities Summary of SectorA groups

2025-07-15 NSHC

https://medium.com/@nshcthreatrecon/2024-activities-summary-of-sectora-groups-eng-bd7af32fb99b

NSHC's 2024 SectorA review describes North Korea-linked groups pursuing strategic intelligence collection and financial gain, with SectorA05/Kimsuky and SectorA01/Lazarus the most active groups in the excerpt. Kimsuky focused on spear-phishing South Korean government, defense, and diplomatic targets using social engineering, customized malicious documents, and backdoors for long-term infiltration. Lazarus targeted financial institutions, cryptocurrency exchanges, defense companies, and other industries through supply-chain attacks, watering holes, and zero-day exploitation to support espionage and foreign-currency acquisition. The report identifies IT and financial organizations as major target sectors, South Korea and the United States as leading target countries, spear-phishing links as a favored initial access method, and exploitation of TeamCity, ActiveMQ, and Ivanti vulnerabilities as notable intrusion paths.

Related Actors

Related Reports

« Back