Active North Korean campaign targeting security researchers

2023-09-07 Google

https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/

Thumbnail for Active North Korean campaign targeting security researchers

Active North Korean campaign targeting security researchers In January 2021, Threat Analysis Group (TAG) publicly disclosed a campaign from government backed actors in North Korea who used 0-day exploits to target security researchers working on vulnerability research and development. Security researcher targeting Similar to the previous campaign TAG reported on, North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits. TAG is aware of at least one actively exploited 0-day being used to target security researchers in the past several weeks.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0eedfd4ab367cc0b6ab804184c315cc… 2023-09-07 2023-09-07
HASH 5977442321a69371795036544688005… 2023-09-07 2023-09-07
HASH 50869d2a713acf406e160d6cde3b442… 2023-09-07 2023-09-07
HASH 2ee435bdafacfd7c5a9ea7e5f95be97… 2023-09-07 2023-09-07
URL https://dbgsymbol.com 2023-09-07 2023-09-07
DOMAIN dbgsymbol.com 2023-09-07 2023-09-07
IPv4 23.106.215.105 2023-09-07 2023-09-07

Related Reports

« Back