North Korean Cyber Espionage Group Targets University Professors

Published:

spot_img

Kimsuky Cyber Attack Targeting Universities Linked to North Korea

In a recent development, the North Korea-linked threat actor, Kimsuky, has been identified in a series of cyber attacks targeting university staff, researchers, and professors for intelligence gathering purposes. Cybersecurity firm Resilience discovered this activity in late July 2024 after spotting an operation security error made by the hackers.

Kimsuky, also known by various aliases such as APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet, Springtail, and Velvet Chollima, is just one of several offensive cyber teams operated by the North Korean government and military.

The group is known for its active engagement in spear-phishing campaigns to deliver custom tools for reconnaissance, data theft, and establishing remote access to infected hosts. They have been using compromised hosts to deploy an obfuscated version of the Green Dinosaur web shell, facilitating file operations and phishing campaigns.

One notable tactic used by Kimsuky involves uploading phishing pages mimicking legitimate login portals for Naver and various universities to capture credentials. The victims are then redirected to a PDF document purporting to be an invitation to the Asan Institute for Policy Studies August Forum.

Researchers at Resilience have also uncovered a custom PHPMailer tool called SendMail, used by Kimsuky to send phishing emails through Gmail and Daum Mail accounts.

To protect against such threats, users are advised to enable multi-factor authentication and carefully scrutinize URLs before logging in. Stay informed about such cyber threats by following us on Twitter and LinkedIn for more exclusive content.

spot_img

Related articles

Recent articles

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...