An continuing effort targeting South Korean government, business, and cryptocurrency sectors has been traced to a nation-state threat actor with ties to North Korea.
The hacking collective known as Kimsuky, which is also known by the names APT43, Black Banshee, Emerald Sleet, Sparkling Pisces, Springtail, TA427, and Velvet Chollima, has been implicated in the attack campaign, which Securonix has named DEEP#DRIVE.
In a report shared with The Hacker News, security researchers Den Iuzvyk and Tim Peck described the activity as a “sophisticated and multi-stage operation,” stating that the attackers successfully infiltrated targeted environments by using customized phishing lures written in Korean and masquerading as authentic documents read more about North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
