"We Are About to Land": How CloudDragon Turns a Nightmare Into Reality
2021-05-07 • Team T5 •
TeamT5's CloudDragon presentation distinguishes the group from other DPRK clusters and frames it as part of the public Kimsuky activity set. The transcript describes CloudDragon targeting South Korea, the United States, Japan, Europe, and sectors including government, education, research, finance, energy, high tech, aerospace, and defense. It also maps infrastructure and malware links across BabyShark, JamBog, TroyBomb, RoseMe, and DomaRAT, and notes COVID-19 themed targeting of vaccine providers and research institutes.
Related Actors
Related Reports
2022-11-28 •
70% Match
CloudDragon’s Credential Factory is Powering Up Its Espionage Activities Against All the Policymakers
Team T5
Shares tags: Youtube, CloudDragon • Same author: Team T5
Shares tag: CloudDragon • Same author: Team T5 • Published within a month
Shares tag: CloudDragon • Same author: Team T5 • Published within a week
Shares tag: CloudDragon • Same author: Team T5
2021-05-21 •
60% Match
#Trend
#CloudDragon
#T1140
#T1071.001
#T1027
#T1204.002
#T1071
#T1518.001
#T1566.001
#T1547.001
#T1053.005
#T1059.001
#T1036.005
#T1574.002
#T1133
#T1055.012
#T1218.011
#T1021.001
#T1574.001
#T1047
#T1560.001
#T1543.003
#T1087.002
#T1482
#T1070.001
#T1003.002
#T1053.002
#T1003.003
Shares tag: CloudDragon • Published within a month
Shares tag: CloudDragon • Same author: Team T5