North Korean hackers reboot espionage operations following December takedown
Suspected North Korean hackers have been running a spearphishing email operation targeting people interested in North Korean refugees, according to new research from ESTsecurity, a South Korea-based security firm. The cyber-espionage group, which ESTsecurity Security Response Center (ESRC) researchers attribute to a group known as Geumseong121, entices its victims into clicking links that look to be about North Korean refugees. But instead of delivering valuable information, the link points recipients to repositories that download malicious files, according to ESRC. The campaign, which ESRC has named “Operation Spy Cloud” since it relies on cloud services, shows the hacking group returning to operations following a setback in December when Microsoft seized 50 websites used by the group in spearphishing campaigns. The group is also widely known as APT37. Following the takedown, the group is working to conceal its activities, according to ESRC. The attackers appear to have opted to prompt users to click links […]
The post North Korean hackers reboot espionage operations following December takedown appeared first on CyberScoop.
Continue reading North Korean hackers reboot espionage operations following December takedown