Monthly Threat Actor Group Intelligence Report, January 2024 (KOR)

2024-03-11 NSHC

https://redalert.nshc.net/2024/03/11/monthly-threat-actor-group-intelligence-report-january-2024-kor/

Thumbnail for Monthly Threat Actor Group Intelligence Report, January 2024 (KOR)

NSHC's January 2024 ThreatRecon report lists SectorA01, SectorA02, SectorA05, SectorA06, and SectorA07 activity across East Asia, Europe, the United States, and other regions. The SectorA entries describe malware disguised as PuTTY, a Korean unification-strategy forum LNK lure that downloads and runs additional PowerShell-delivered malware in memory, Foxit PDF Reader update impersonation, a macOS Mach-O file disguised with a JPG extension, and a patent-fee CHM lure. The report assesses SectorA activity as continuing to pursue South Korea-related political and diplomatic intelligence while also supporting financially motivated operations.

Related Actors

Related Reports

« Back