Uptime Hamster: 11d 20h 42mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Operation Earth Kitsune

Operation Earth Kitsune

0 incidentes 0 paises 0 sectores apt KR Ultimo: -
Ver en IntelTracker → APTTrail →
Operation Earth Kitsune is a cyber espionage campaign that first emerged around 2019, initially identified through its use of the SLUB malware. Over time, the group has evolved its tactics, moving from C2 communications abusing platforms like Slack and GitHub to utilizing Mattermost, and shifting from solely relying on browser exploits to incorporating social engineering with fake installers. Assessed with high confidence to be of North Korean origin due to strong associations with APT37, also known as Reaper or Group 123, and indicators such as the use of Korean language in developer environments and the deliberate blocking of South Korean IP addresses from compromised sites. The group's primary motivation is information theft and espionage, specifically targeting individuals globally who are interested in North Korean affairs. What sets this group apart is its consistent use of watering hole attacks on North Korea-related websites and the continuous development of custom backdoors, i

Actores similares

Earth Kitsuneapt · 0apt-earthberberokaactor · 1apt-earthhundunactor · 1apt-earthwendigoactor · 1earthkapreactor · 1Earth Luscaapt · 1Operation Wocaoapt · 1earth-berberokaactor · 1earth-kapreactor · 1influence-operationsactor · 1
Motivacion