Monthly Threat Actor Group Intelligence Report, January 2024 (JPN)

2024-04-03 NSHC

https://redalert.nshc.net/2024/04/03/monthly-threat-actor-group-intelligence-report-january-2024-jpn/

Thumbnail for Monthly Threat Actor Group Intelligence Report, January 2024 (JPN)

NSHC's January 2024 ThreatRecon report lists SectorA as the most active DPRK-relevant group family in a broad monthly roundup of 26 hacking groups. SectorA01 used malware disguised as PuTTY against targets in countries including Spain, the United States, Germany, Brazil, France, Serbia, Bangladesh, Turkey, Israel, India, Russia, Switzerland, and South Korea. SectorA02 used a Korea Unification Strategy Forum-themed LNK lure that downloaded additional malware through PowerShell, while SectorA05 abused a Foxit PDF Reader update theme and SectorA07 used a patent-fee CHM lure. NSHC assesses SectorA as pursuing South Korea-related political and diplomatic intelligence while also conducting financially motivated operations worldwide.

Related Actors

Related Reports

« Back