Tag: Kimsuky Hackers

North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks
News

North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks

Kimsuky, a threat actor associated with North Korea, has been implicated in a number of phishing attacks that use email messages sent from Russian sender addresses in order to steal credentials. Up until early September, phishing emails were primarily delivered via email providers in Korea and Japan, according to Genians, a cybersecurity company based in South Korea. Then, starting in the middle of September, certain phishing emails that appeared to be from Russia were noticed. VK's Mail.ru email service, which offers five distinct alias domains—mail.ru, internet.ru, bk.ru, inbox.ru, and list.ru—is being abused in this way. According to Genians, the Kimsuky actors have been using all of the sender domains described above for phishing attempts read more about North Korean Kimsuky ...
North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware
News

North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware

As part of a reconnaissance and data exfiltration operation, the North Korean advanced persistent threat (APT) organisation known as Kimsuky has been seen deploying a piece of proprietary malware named RandomQuery. According to a report released today by SentinelOne researchers Aleksandar Milenkoski and Tom Hegel, "Kimsuky has been consistently distributing custom malware as part of reconnaissance campaigns to enable subsequent attacks." According to the cybersecurity company, the ongoing targeted campaign is particularly aimed at information services as well as groups that assist human rights advocates read more North Korean Kimsuky Hackers Strike Again with Reconnaissance Malware. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cyb...