logo

2021 Fall/Winter Threat Update

ID: 38a44bce-0ff3-4429-b8bb-83923fe28e41

STIX ID: report--38a44bce-0ff3-4429-b8bb-83923fe28e41

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2021-11-18

Last Modified Date: 2021-11-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint details TA406 — a DPRK-aligned threat actor — which in 2021 executed near-weekly credential-phishing campaigns against researchers, academics, NGOs, media and government targets, sometimes delivering malware (e.g., FatBoy downloader, YoreKey keylogger) and conducting financially motivated schemes (sextortion, cryptocurrency-themed lures); the report includes TTPs (PHPMailer/Star tools, PHProxy, Basic HTTP auth, PDF decoys), campaign timing/targeting analysis, malware behavior, IoCs (domains, hosts, hashes, IPs) and detection rules.