Monthly Threat Actor Group Intelligence Report, November 2024 (KOR)
2025-01-08 • NSHC •
NSHC's November 2024 Korean threat-actor intelligence report describes multiple observed intrusion patterns, including malicious LNK files themed around China-North Korea policy, VHDX lures disguised as Chinese embassy invitations, and backdoors that steal files or capture screens. The report also notes cloud-service exfiltration through pCloud and Yandex, credential and Windows token abuse followed by Play ransomware activity, and macOS persistence through modification of the zsh environment file. These observations provide broad TTP coverage for DPRK-linked and adjacent APT monitoring.
Related Actors
Related Reports
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC • Published within a month
2025-01-17 •
84% Match
#Trend
#SectorA
#SectorA05
#SectorA01
#SectorA06
#SectorA07
#SectorA03
#SectorA04
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC • Published within a month
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC
2024-11-20 •
74% Match
#Trend
#SectorA
#SectorA05
#SectorA01
#SectorA06
#SectorA07
#SectorA03
#SectorA04
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC
2024-11-04 •
74% Match
#Trend
#SectorA
#SectorA05
#SectorA01
#SectorA06
#SectorA07
#SectorA03
#SectorA04
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC
2024-11-04 •
74% Match
#Trend
#SectorA
#SectorA05
#SectorA01
#SectorA02
#SectorA06
#SectorA07
#SectorA04
Shares tags: Trend, SectorA, SectorA01 • Same author: NSHC