Targeted Threats Research - South & North Korea (a breakdown of 3 years of threat research in Korea)
2025-02-10 • 0x0v1 •
https://www.0x0v1.com/targeted-threats-research-south-north-korea/
The report examines nearly three years of targeted digital threats against five civil society organizations in South Korea, with a focus on activists, journalists, and human rights defenders working on North Korea-related issues. It argues that these groups face state-backed targeting from external governments, including North Korea and China, and that direct engagement with victims gives civil society responders evidence that private-sector telemetry may miss. The methodology combines manual analysis of emails, malware, social engineering, mobile campaigns, forensic artifacts, passive DNS, and open-source threat intelligence with clustering in a private MISP instance. For DPRK tracking, the source is most useful as a victim-centered view of campaigns against South Korean North Korea human rights and unification advocacy communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 83b97826c43808c5caa1b69c9c7cbeb0 | 2025-02-10 | 2025-02-10 |
| HASH | 44b3f46a370faf94cc51386b4ccaab83 | 2025-02-10 | 2025-02-10 |
| HASH | 5de4215ba91bd52ae7371a049c23c82… | 2025-02-10 | 2025-02-10 |
| HASH | 375f71617fa5171a7ed24dacc1fd7f6… | 2025-02-10 | 2025-02-10 |
| HASH | 6e3d7cdb6a506eba10f719c2ad5e5ef… | 2025-02-10 | 2025-02-10 |
| [email protected] | 2025-02-10 | 2025-02-10 | |
| HASH | 5fec6e533fb9741997530a3d43b60ee… | 2024-03-01 | 2025-02-10 |
| URL | https://work3.b4a.app/download.… | 2024-03-01 | 2025-02-10 |
| URL | https://work3.b4a.app/download.… | 2024-03-01 | 2025-02-10 |
| URL | https://.work3.b4a.app/ | 2024-03-01 | 2025-02-10 |
| HASH | c49b4d370ad0dcd1e28ee8f525ac8e3… | 2022-12-07 | 2025-02-10 |