Phishing Attack Activities: Threat Actors in Sheep’s Clothing (ENG)
2023-04-18 • NSHC •
NSHC ThreatRecon reports that SectorA groups, especially SectorA05, sharply increased phishing activity in 2022, with South Korea accounting for nearly all observed targeting. The activity focused on research centers, government workers, education, NGOs, media, finance, and people connected to North Korea policy, using email, messengers, social media, and portal-account phishing to steal credentials. The excerpt highlights lures aimed at researchers and North Korea-related personnel, including emails that linked victims to phishing pages rather than delivering real attachments. The DPRK-relevant value is the victimology and method: SectorA05 used low-complexity credential theft to support intelligence collection against South Korean policy, diplomatic, military, and research targets, and also pursued investor accounts for financially motivated access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | myartsonline.com | 2020-09-30 | 2024-09-05 |
| DOMAIN | eu5.net | 2023-04-05 | 2023-04-18 |
| DOMAIN | eu3.org | 2023-04-05 | 2023-04-18 |
| DOMAIN | daum-privacy.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | googlmeil.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | infinityfreeapp.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | kakaocop.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | eu3.biz | 2023-04-05 | 2023-04-18 |
| DOMAIN | dankook.onedviver.epizy.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | glitch.me | 2023-04-05 | 2023-04-18 |
| DOMAIN | fleek.co | 2023-04-05 | 2023-04-18 |
| DOMAIN | nid.daurn.in.net | 2023-04-05 | 2023-04-18 |
| DOMAIN | kisa.42web.io | 2023-04-05 | 2023-04-18 |
| DOMAIN | daurn.in.net | 2023-04-05 | 2023-04-18 |
| IPv4 | 162.216.224.39 | 2023-04-05 | 2023-04-18 |
| DOMAIN | accounts.qocple.epizy.com | 2022-10-26 | 2023-04-18 |
| DOMAIN | 42web.io | 2022-08-25 | 2023-04-18 |
| DOMAIN | naver.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | kakao.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | snu.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | epizy.com | 2020-09-04 | 2023-04-18 |