Monthly Threat Actor Group Intelligence Report, January 2024 (KOR)
2024-03-11 • NSHC •
NSHC's January 2024 ThreatRecon report lists SectorA01, SectorA02, SectorA05, SectorA06, and SectorA07 activity across East Asia, Europe, the United States, and other regions. The SectorA entries describe malware disguised as PuTTY, a Korean unification-strategy forum LNK lure that downloads and runs additional PowerShell-delivered malware in memory, Foxit PDF Reader update impersonation, a macOS Mach-O file disguised with a JPG extension, and a patent-fee CHM lure. The report assesses SectorA activity as continuing to pursue South Korea-related political and diplomatic intelligence while also supporting financially motivated operations.
Related Actors
Related Reports
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA • Same author: NSHC • Published within a month