Headlines

“Unpacking the Latest North Korean APT Tactics: A Deeper Look into Malicious OneDrive Links”

"Unpacking the Latest North Korean APT Tactics: A Deeper Look into Malicious OneDrive Links"malware,NorthKorea,APT,OneDrive,cyberattack,tactics
North Korean cyber espionage group Kimsuky has been observed employing a new spear-phishing campaign aimed at staff from Korea Risk Group (KRG) and several universities, according to researchers at SentinelLabs. The attack uses Microsoft OneDrive links contained in documents equipped with malicious macros, which then drop ReconShark malware. ReconShark is part of a broader malware system known as BabyShark. The new malware can exfiltrate data, including key information on detection mechanisms and hardware details, which is used to access targeted networks. The cyber espionage group is also showing greater attention to detail in its crafting of emails to ensure they appear legitimate to recipients. The group has previously been linked to cyber espionage operations focused on research institutions, think tanks, and pharmaceutical companies. The new campaign suggests that Kimsuky is expanding its targeting to also include academic institutions and that organizations need to adopt good email security practices to avoid compromise.
Cybersecurity-malware,NorthKorea,APT,OneDrive,cyberattack,tactics


"Unpacking the Latest North Korean APT Tactics: A Deeper Look into Malicious OneDrive Links"
<< photo by Dan Nelson >>

You might want to read !