Monthly Threat Actor Group Intelligence Report, June 2023 (KOR)
2023-08-16 • NSHC •
https://redalert.nshc.net/2023/08/16/monthly-threat-actor-group-intelligence-report-june-2023-kor/
NSHC ThreatRecon’s June 2023 monthly report summarizes activity from 32 threat-actor groups, with SectorA accounting for the largest share of observed activity. The DPRK-relevant SectorA section covers five groups: SectorA01 exploiting Korean web-security and asset-management RCE flaws to download and run malware, SectorA02 using LNK lures disguised as North Korean human-rights film cooperation requests, SectorA05 sending CHM malware in phishing emails themed around North Korean human-rights organizations, SectorA06 targeting macOS users with a fake PDF viewer and Microsoft Azure protected-document lure, and SectorA07 using ZIP-packed LNK lures about appraisal cooperation to collect system information. The report characterizes continuing SectorA objectives as collecting high-value political, diplomatic, and government-related intelligence tied to Korea while also pursuing financially motivated hacking worldwide.