Active North Korean campaign targeting security researchers
2023-09-07 • Google •
Active North Korean campaign targeting security researchers In January 2021, Threat Analysis Group (TAG) publicly disclosed a campaign from government backed actors in North Korea who used 0-day exploits to target security researchers working on vulnerability research and development. Security researcher targeting Similar to the previous campaign TAG reported on, North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits. TAG is aware of at least one actively exploited 0-day being used to target security researchers in the past several weeks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0eedfd4ab367cc0b6ab804184c315cc… | 2023-09-07 | 2023-09-07 |
| HASH | 5977442321a69371795036544688005… | 2023-09-07 | 2023-09-07 |
| HASH | 50869d2a713acf406e160d6cde3b442… | 2023-09-07 | 2023-09-07 |
| HASH | 2ee435bdafacfd7c5a9ea7e5f95be97… | 2023-09-07 | 2023-09-07 |
| URL | https://dbgsymbol.com | 2023-09-07 | 2023-09-07 |
| DOMAIN | dbgsymbol.com | 2023-09-07 | 2023-09-07 |
| IPv4 | 23.106.215.105 | 2023-09-07 | 2023-09-07 |