MONTHLY THREAT ACTOR GROUP INTELLIGENCE REPORT, JANUARY 2022
2022-04-08 • NSHC •
NSHC’s January 2022 ThreatRecon report identifies three North Korea-supported SectorA groups active during the period: SectorA02, SectorA05, and SectorA07. SectorA02 targeted South Korea-based workers involved in North Korea policy with phishing emails disguised as credit-card payment bills, while SectorA05 used HWP malware disguised as North Korea policy documents in South Korea and Bulgaria. SectorA07 targeted government and diplomatic personnel connected to a specific country from activity observed in Russia. NSHC assessed SectorA activity as continuing to support political and diplomatic intelligence collection against South Korea while also pursuing global operations for financial resources.