216.73.216.226

Suspected DPRK Phishing Campaign Targets Naver; Separate Apple Domain Spoofing Cluster Identified

· Published 30/10/2024 15:14 · Modified 30/10/2024 21:58

Export JSON

Essential information

Published
30/10/2024 15:14
Modified
30/10/2024 21:58
Tags
2024-10-30 apple credential-theft domain spoofing dprk infrastructure analysis naver phishing tls certificates
Related entities
8 techniques (mitre), 1 others

Description

Researchers discovered a potential North Korean campaign targeting , a major South Korean tech platform. The investigation revealed an exposed directory containing pages designed to steal user credentials. Separately, an infrastructure cluster was identified using domains and certificates impersonating . Both findings align with tactics commonly associated with cyber operations. The server, hosted in Seoul, contained multiple folders with files for credential theft. Additionally, a cluster of IPs across various countries was found sharing and domains spoofing . The use of low-cost domains, Let's Encrypt certificates, and frequent infrastructure changes are consistent with known threat actor behaviors.

External references