XenoRAT malware campaign hits multiple embassies in South Korea

Foreign embassies in South Korea are the target of a state-sponsored espionage campaign that uses rogue GitHub repositories to spread XenoRAT malware.

Researchers at Trellix claim that the campaign, which has been going on since March, has launched at least 19 spearphishing attempts against valuable targets.

According to the experts, there are indications that more closely resemble Chinese-based agents, even though the infrastructure and tactics are similar to those of North Korean actor Kimsuky (APT43).

Between early March and July, the attacks took place in three stages, each with its own unique email lures. The first email found targeted an embassy in Central Europe, and the initial digging began in March. The threat actor shifted to using more sophisticated lures and diplomatic targeting in May.

The themes included phony invitations to meetings, official letters, and events, frequently issued by posing as diplomats read more about XenoRAT malware campaign hits multiple embassies in South Korea.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *