Update on campaign targeting security researchers
2021-03-31 • Google •
Google TAG says the North Korean government-backed actors targeting security researchers expanded their operation by creating a fake offensive-security company called SecuriElite on March 17. The site and associated LinkedIn and Twitter personas posed as security researchers, recruiters or company staff, continuing the earlier tactic of building credibility with exploitation-focused targets. TAG notes that prior attacker-controlled sites used a hosted PGP key as a lure to a browser exploit, and although SecuriElite had not yet served malicious content, Google added it to Safe Browsing as a precaution. The report also lists attacker-controlled domains and social accounts for defensive tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | devguardmap.org | 2021-03-31 | 2021-11-11 |
| DOMAIN | redeastbay.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | cutesaucepuppy.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | bestwing.org | 2021-03-31 | 2021-03-31 |
| DOMAIN | spotchannel02.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | hotelboard.org | 2021-03-31 | 2021-03-31 |
| DOMAIN | securielite.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | codebiogblog.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | hireproplus.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | mediterraneanroom.org | 2021-03-31 | 2021-03-31 |
| DOMAIN | coldpacific.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | regclassboard.com | 2021-03-31 | 2021-03-31 |
| DOMAIN | wileprefgurad.net | 2021-03-31 | 2021-03-31 |