2021 Fall/Winter Threat Update
ID: 38a44bce-0ff3-4429-b8bb-83923fe28e41
STIX ID: report--38a44bce-0ff3-4429-b8bb-83923fe28e41
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2021-11-18
Last Modified Date: 2021-11-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint details TA406 — a DPRK-aligned threat actor — which in 2021 executed near-weekly credential-phishing campaigns against researchers, academics, NGOs, media and government targets, sometimes delivering malware (e.g., FatBoy downloader, YoreKey keylogger) and conducting financially motivated schemes (sextortion, cryptocurrency-themed lures); the report includes TTPs (PHPMailer/Star tools, PHProxy, Basic HTTP auth, PDF decoys), campaign timing/targeting analysis, malware behavior, IoCs (domains, hosts, hashes, IPs) and detection rules.
