The National Cyber Security Directorate (DNSC) has alerted users to an active phishing campaign attributed to the North Korean group Konni. It uses malicious LNK files attached in emails to infect targeted systems. The malware is downloaded through trusted cloud infrastructures such as Dropbox and Google Drive. Konni, which has been active since 2014, focuses on data exfiltration and has been associated with cyberattacks in South Korea, Russia, the US and Europe, with similar techniques to other state-sponsored groups.
Sources
Latest News
21:57
21:39
21:35
21:19
21:09
See more news