Monthly Threat Actor Group Intelligence Report, June 2023 (ENG)
2023-08-23 • NSHC •
https://redalert.nshc.net/2023/08/23/monthly-threat-actor-group-intelligence-report-june-2023-eng/
NSHC ThreatRecon’s June 2023 intelligence report identifies SectorA activity as the most prominent threat-actor category in the collection period and describes five SectorA groups active across South Korea and other countries. SectorA01 abused remote-code-execution vulnerabilities in South Korean web security and asset-management software to download and execute malware, while SectorA02 used LNK files disguised as cooperation documents for a North Korean human-rights film screening. SectorA05 sent phishing emails with CHM attachments themed around North Korean human-rights organizations to steal information, SectorA06 targeted macOS users with malware disguised as a PDF viewer, and SectorA07 used ZIP-delivered LNK files and scripts to collect system information. The report characterizes SectorA operations as long-running intelligence collection against South Korean political and diplomatic activity, alongside broader global targeting for financial resources.