2023_Group123_threat_inteligence_report_BitB.pdf
ID: 044b690b-ea30-4224-9f39-4091ae2dfedd
STIX ID: report--044b690b-ea30-4224-9f39-4091ae2dfedd
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2023-08-31
Last Modified Date: 2023-08-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Genians Security Center report documents a targeted BitB (Browser-in-the-Browser) phishing campaign impersonating the LiNK NGO to steal credentials from North Korea-related activists and organizations. The attackers used SSO-style popups and short links that redirect to a fake libertynorthkorea.org site; investigation links multiple domains, IPs and MD5 hashes to APT37 infrastructure and identifies follow-on LNK/ROKRAT malware and beaconing. The report includes IoCs (domains, IPs, hashes), detection tips for BitB popups, and remediation/detection recommendations including EDR policies.
