XenoRAT malware campaign hits multiple embassies in South Korea
Foreign embassies in South Korea are the target of a state-sponsored espionage campaign that uses rogue GitHub repositories to spread XenoRAT malware.
Researchers at Trellix claim that the campaign, which has been going on since March, has launched at least 19 spearphishing attempts against valuable targets.
According to the experts, there are indications that more closely resemble Chinese-based agents, even though the infrastructure and tactics are similar to those of North Korean actor Kimsuky (APT43).
Between early March and July, the attacks took place in three stages, each with its own unique email lures. The first email found targeted an embassy in Central Europe, and the initial digging began in March. The threat actor shifted to using more sophisticated lures and diplomat...

