« 2024 »

654 reports

2024-03-10 • IBM

ITG16 is described as a North Korean state-sponsored threat group active since at least 2012. The group has traditionally targeted South Korean diplomatic and national security personnel, human rights groups, media, utilities, and think tanks. Its operati…

#ITG16
2024-03-09 • somedieyoung ZZ

The excerpt analyzes a PowerShell backdoor associated by the author with Kimsucky, a North Korea-based APT described as using malicious documents, social engineering, spear phishing, and watering-hole techniques against organizations in South Korea, Japan…

#Kimsuky #T1027.004