Monthly Threat Actor Group Intelligence Report, April 2023 (ENG)
2023-06-21 • NSHC •
https://redalert.nshc.net/2023/06/21/monthly-threat-actor-group-intelligence-report-april-2023-eng/
NSHC ThreatRecon’s April 2023 monthly intelligence report identifies SectorA activity as the most prominent threat-actor grouping in the period, with five SectorA clusters observed across South Korea and other regions. The DPRK-relevant section describes SectorA01 supply-chain activity against a VoIP provider, SectorA02 ISO/LNK lures themed around North Korean diplomacy, SectorA05 spear-phishing of diplomacy and national-security workers, SectorA06 OneNote cryptocurrency lures, and SectorA07 tax-themed LNK malware. Reported final-stage behavior included system and browser information collection, cloud-service exfiltration, DLL execution, privilege gain, and batch-script collection of process, file, installed-program, and network data. NSHC frames SectorA operations as continuing efforts to collect information on South Korean political and diplomatic activity while also pursuing financial resources globally.