CloudDragon’s Credential Factory is Powering Up Its Espionage Activities Against All the Policymakers
2022-11-28 • Team T5 •
TeamT5's talk describes CloudDragon as a North Korean Kimsuky subgroup that runs espionage and cybercrime operations against policymakers and related organizations. The transcript focuses on a credential factory workflow built around phishing, proxy mirror phishing, and phishing bots that can relay credentials and OTPs to real login pages. CloudDragon then uses compromised accounts, private documents, malicious documents, and service or vendor access to expand campaigns against government, education, research, NGO, media, technology, UN, US, Japanese, and South Korean targets.
Related Actors
Related Reports
Shares tags: Youtube, CloudDragon • Same author: Team T5
Shares tag: CloudDragon • Same author: Team T5
Shares tag: CloudDragon • Same author: Team T5
Shares tag: CloudDragon • Same author: Team T5
Shares tag: CloudDragon • Same author: Team T5
2021-05-21 •
40% Match
#Trend
#CloudDragon
#T1140
#T1071.001
#T1027
#T1204.002
#T1071
#T1518.001
#T1566.001
#T1547.001
#T1053.005
#T1059.001
#T1036.005
#T1574.002
#T1133
#T1055.012
#T1218.011
#T1021.001
#T1574.001
#T1047
#T1560.001
#T1543.003
#T1087.002
#T1482
#T1070.001
#T1003.002
#T1053.002
#T1003.003
Shares tag: CloudDragon