Update on campaign targeting security researchers

2021-03-31 Google

https://blog.google/threat-analysis-group/update-campaign-targeting-security-researchers/?fbclid=IwAR0EaDQidia5L8QaaDsvgrHs84Jka5ZizooH9_U3oNQMLtFVo4F5Xic9qQo

Thumbnail for Update on campaign targeting security researchers

Google TAG says the North Korean government-backed actors targeting security researchers expanded their operation by creating a fake offensive-security company called SecuriElite on March 17. The site and associated LinkedIn and Twitter personas posed as security researchers, recruiters or company staff, continuing the earlier tactic of building credibility with exploitation-focused targets. TAG notes that prior attacker-controlled sites used a hosted PGP key as a lure to a browser exploit, and although SecuriElite had not yet served malicious content, Google added it to Safe Browsing as a precaution. The report also lists attacker-controlled domains and social accounts for defensive tracking.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN devguardmap.org 2021-03-31 2021-11-11
DOMAIN redeastbay.com 2021-03-31 2021-03-31
DOMAIN cutesaucepuppy.com 2021-03-31 2021-03-31
DOMAIN bestwing.org 2021-03-31 2021-03-31
DOMAIN spotchannel02.com 2021-03-31 2021-03-31
DOMAIN hotelboard.org 2021-03-31 2021-03-31
DOMAIN securielite.com 2021-03-31 2021-03-31
DOMAIN codebiogblog.com 2021-03-31 2021-03-31
DOMAIN hireproplus.com 2021-03-31 2021-03-31
DOMAIN mediterraneanroom.org 2021-03-31 2021-03-31
DOMAIN coldpacific.com 2021-03-31 2021-03-31
DOMAIN regclassboard.com 2021-03-31 2021-03-31
DOMAIN wileprefgurad.net 2021-03-31 2021-03-31

Related Reports

« Back