Phishing Attack Activities: Threat Actors in Sheep’s Clothing (ENG)
This report includes the analysis of the status of phishing attacks by the SectorA group analyzed by the ThreatRecon team in 2022.
This report includes the analysis of the status of phishing attacks by the SectorA group analyzed by the ThreatRecon team in 2022.
본 보고서에서는 2022년 한 해 동안ThreatRecon Team에서 분석한 SectorA 그룹들의 피싱 공격 현황을 분석한 결과를 포함하고 있다.
In early January 2019, an email containing malware was distributed to 77 reporters from the Unification Ministry of South Korea. We analysed these malware and identified them as malware used by SectorA05, and we confirm that they have been using a specific C2 server located in Korea for at least 26 months continuously. We decided to group these wave of attacks under what we call “Operation Kitty Phishing”.