Monthly Threat Actor Group Intelligence Report, November 2024 (ENG)

2025-02-07 NSHC

https://redalert.nshc.net/2025/02/07/monthly-threat-actor-group-intelligence-report-november-2024-eng/

Thumbnail for Monthly Threat Actor Group Intelligence Report, November 2024 (ENG)

NSHC reports five SectorA clusters active in November 2024, with targeting across South Korea, the United States, the United Kingdom, Russia, Japan, and other regions. SectorA01 abused remote hiring processes and fake identities to obtain jobs and steal sensitive data, while SectorA02 used a North Korea policy-themed LNK lure to deploy a backdoor that exfiltrated files through pCloud and Yandex. SectorA03 used a VHDX disguised as a Chinese embassy invitation to steal files, take screenshots, and run additional malware, and SectorA04 showed stolen-credential access, token manipulation, and possible collaboration with Play ransomware actors. SectorA06 targeted cryptocurrency and sensitive information on macOS by modifying ~/.zshenv for persistence.

Related Actors

Related Reports

« Back