Cyber Security

North Korea-backed Kimsuky Targets blue kekek system not listed in new event

The campaign targets South Korea and Japan

Based on an analysis of campaign infrastructure, threat actors have been attacking South Korea, China, Japan, Germany, Singapore, South Africa, the Netherlands, Mexico, Vietnam, Belgium, the United Kingdom, Canada, Thailand, Thailand and Poland.

However, AHNLAB researchers can only retrieve samples of phishing emails sent to South Korea and Japan. “These threat actors have been attacking South Korea’s software, energy and finance industries since October 2023,” the researchers said.

As an indicator of compromise (IOC), researchers share a list of the hashing features (MD5), URLs, and domain names (FQDNs) that the security team can set up for detection alerts.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button