Suspected North Korean Cyber Espionage Campaign Targets Multiple Foreign Ministries and Think Tanks

2019-08-21 Anomali

https://www.anomali.com/blog/suspected-north-korean-cyber-espionage-campaign-targets-multiple-foreign-ministries-and-think-tanks

Thumbnail for Suspected North Korean Cyber Espionage Campaign Targets Multiple Foreign Ministries and Think Tanks

Anomali observed a suspected North Korean cyber-espionage phishing campaign after finding a fake login page for a French Ministry for Europe and Foreign Affairs portal. Infrastructure analysis showed a broader campaign targeting three Ministry of Foreign Affairs agencies, Stanford University, RUSI, Congressional Research Service, United Nations-related entities, and multiple email service providers. The campaign used credential-harvesting domains such as doc-view.work and web-line.work, including subdomains that impersonated diplomatic portals, secure email services, Gmail, Yahoo, Outlook, OneDrive, and other online services. Anomali reported infrastructure overlap with known North Korean actors, including shared domains and hosting, and highlighted a likely victim connected to sanctions and North Korea-related diplomatic work. The activity matters because it shows credential theft infrastructure aimed at organizations involved in foreign policy, research, diplomacy, and sanctions work.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rive.storage.com 2019-08-21 2019-08-21
DOMAIN accounts.lives.com 2019-08-21 2019-08-21
DOMAIN account.googlie.com 2019-08-21 2019-08-21
DOMAIN onu.delegfrance.org 2019-08-21 2019-08-21
DOMAIN accounts.outlooks.com 2019-08-21 2019-08-21
DOMAIN delegefrance.org 2019-08-21 2019-08-21
DOMAIN brica.de 2019-08-21 2019-08-21
DOMAIN drive.storage.com 2019-08-21 2019-08-21
DOMAIN login.ymail.com 2019-08-21 2019-08-21
IPv4 157.7.184.15 2019-08-21 2019-08-21

Related Reports

« Back