North Korean IT Worker Network Tied to BeaverTail Phishing Campaign

North Korean IT Worker Network Tied to BeaverTail Phishing Campaign

Unit 42, Palo Alto’s research team, observed that a North Korean IT worker activity cluster tracked as CL-STA-0237 and likely operating from Laos, was involved in recent phishing attacks using BeaverTail-infected video conference apps.?

Over the past 12 months, the campaign has evolved, with new malware versions including a downloader compiled using the cross-platform Qt framework. This allows attackers to deploy malware on both macOS and Windows systems from a single source code. Additionally, code updates have been made to the InvisibleFerret backdoor, which enables further control of infected devices.?

Read more here.

要查看或添加评论,请登录

X Cyber Group (XCyber?)的更多文章

社区洞察

其他会员也浏览了