Kimsuky__2021__D2T1_-_The_Phishermen_-_Dissecting_Phishing_Techniques_of_CloudDragon_APT_-_Linda_Kuo_Zih-Cing_Liao.pdf
ID: 97121c80-f47a-4619-90ee-82d591c82f48
STIX ID: report--97121c80-f47a-4619-90ee-82d591c82f48
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2021-05-28
Last Modified Date: 2021-05-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This presentation analyzes CloudDragon (Kimsuky-related) phishing campaigns and toolsets, detailing delivery methods (PHPMailer, SendGrid, proxy mirrors, phishing bots), phishing techniques including 2FA interception, and malware families (BabyShark, JamBog) used for credential theft, screen/keyboard monitoring, persistence and remote command-and-control.
