Operation Earth Kitsune
0 incidentes
0 paises
0 sectores
apt KR Ultimo: -
Operation Earth Kitsune is a cyber espionage campaign that first emerged around 2019, initially identified through its use of the SLUB malware. Over time, the group has evolved its tactics, moving from C2 communications abusing platforms like Slack and GitHub to utilizing Mattermost, and shifting from solely relying on browser exploits to incorporating social engineering with fake installers. Assessed with high confidence to be of North Korean origin due to strong associations with APT37, also known as Reaper or Group 123, and indicators such as the use of Korean language in developer environments and the deliberate blocking of South Korean IP addresses from compromised sites. The group's primary motivation is information theft and espionage, specifically targeting individuals globally who are interested in North Korean affairs. What sets this group apart is its consistent use of watering hole attacks on North Korea-related websites and the continuous development of custom backdoors, i