Phishing Attack Activities: Threat Actors in Sheep’s Clothing (ENG)

2023-04-18 NSHC

https://redalert.nshc.net/2023/04/18/phishing-attack-activities-threat-actors-in-sheeps-clothing-eng/

Thumbnail for Phishing Attack Activities: Threat Actors in Sheep’s Clothing (ENG)

NSHC ThreatRecon reports that SectorA groups, especially SectorA05, sharply increased phishing activity in 2022, with South Korea accounting for nearly all observed targeting. The activity focused on research centers, government workers, education, NGOs, media, finance, and people connected to North Korea policy, using email, messengers, social media, and portal-account phishing to steal credentials. The excerpt highlights lures aimed at researchers and North Korea-related personnel, including emails that linked victims to phishing pages rather than delivering real attachments. The DPRK-relevant value is the victimology and method: SectorA05 used low-complexity credential theft to support intelligence collection against South Korean policy, diplomatic, military, and research targets, and also pursued investor accounts for financially motivated access.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN myartsonline.com 2020-09-30 2024-09-05
DOMAIN eu5.net 2023-04-05 2023-04-18
DOMAIN eu3.org 2023-04-05 2023-04-18
DOMAIN daum-privacy.com 2023-04-05 2023-04-18
DOMAIN googlmeil.com 2023-04-05 2023-04-18
DOMAIN infinityfreeapp.com 2023-04-05 2023-04-18
DOMAIN kakaocop.com 2023-04-05 2023-04-18
DOMAIN eu3.biz 2023-04-05 2023-04-18
DOMAIN dankook.onedviver.epizy.com 2023-04-05 2023-04-18
DOMAIN glitch.me 2023-04-05 2023-04-18
DOMAIN fleek.co 2023-04-05 2023-04-18
DOMAIN nid.daurn.in.net 2023-04-05 2023-04-18
DOMAIN kisa.42web.io 2023-04-05 2023-04-18
DOMAIN daurn.in.net 2023-04-05 2023-04-18
IPv4 162.216.224.39 2023-04-05 2023-04-18
DOMAIN accounts.qocple.epizy.com 2022-10-26 2023-04-18
DOMAIN 42web.io 2022-08-25 2023-04-18
DOMAIN naver.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN kakao.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN snu.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN epizy.com 2020-09-04 2023-04-18

Related Actors

Related Reports

« Back