Kimsuky, a threat actor associated with North Korea, has been implicated in a number of phishing attacks that use email messages sent from Russian sender addresses in order to steal credentials.
Up until early September, phishing emails were primarily delivered via email providers in Korea and Japan, according to Genians, a cybersecurity company based in South Korea. Then, starting in the middle of September, certain phishing emails that appeared to be from Russia were noticed.
VK’s Mail.ru email service, which offers five distinct alias domains—mail.ru, internet.ru, bk.ru, inbox.ru, and list.ru—is being abused in this way.
According to Genians, the Kimsuky actors have been using all of the sender domains described above for phishing attempts read more about North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
