Suspected North Korean Cyber Espionage Campaign Targets Multiple Foreign Ministries and Think Tanks
2019-08-21 • Anomali •
Anomali observed a suspected North Korean cyber-espionage phishing campaign after finding a fake login page for a French Ministry for Europe and Foreign Affairs portal. Infrastructure analysis showed a broader campaign targeting three Ministry of Foreign Affairs agencies, Stanford University, RUSI, Congressional Research Service, United Nations-related entities, and multiple email service providers. The campaign used credential-harvesting domains such as doc-view.work and web-line.work, including subdomains that impersonated diplomatic portals, secure email services, Gmail, Yahoo, Outlook, OneDrive, and other online services. Anomali reported infrastructure overlap with known North Korean actors, including shared domains and hosting, and highlighted a likely victim connected to sanctions and North Korea-related diplomatic work. The activity matters because it shows credential theft infrastructure aimed at organizations involved in foreign policy, research, diplomacy, and sanctions work.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rive.storage.com | 2019-08-21 | 2019-08-21 |
| DOMAIN | accounts.lives.com | 2019-08-21 | 2019-08-21 |
| DOMAIN | account.googlie.com | 2019-08-21 | 2019-08-21 |
| DOMAIN | onu.delegfrance.org | 2019-08-21 | 2019-08-21 |
| DOMAIN | accounts.outlooks.com | 2019-08-21 | 2019-08-21 |
| DOMAIN | delegefrance.org | 2019-08-21 | 2019-08-21 |
| DOMAIN | brica.de | 2019-08-21 | 2019-08-21 |
| DOMAIN | drive.storage.com | 2019-08-21 | 2019-08-21 |
| DOMAIN | login.ymail.com | 2019-08-21 | 2019-08-21 |
| IPv4 | 157.7.184.15 | 2019-08-21 | 2019-08-21 |