Monthly Threat Actor Group Intelligence Report, August 2024 (KOR)
2024-10-10 • NSHC •
https://redalert.nshc.net/2024/10/10/monthly-threat-actor-group-intelligence-report-august-2024-kor/
NSHC's August 2024 threat-actor intelligence report summarizes activity from 29 tracked hacking groups, with SectorA clusters representing multiple North Korea-linked operations. The North Korea section describes SectorA02 activity in South Korea involving exploitation of a Microsoft Windows scripting-engine vulnerability, SectorA04 activity against Japan, the United States, Russia, and South Korea using a security-software management-system weakness, and SectorA05 operations using CHM files and DLL side-loading for command-and-control execution. It also notes SectorA06 cryptocurrency-themed macOS targeting with Mach-O malware that downloads and runs additional payloads.