Researchers from Palo Alto Networks observed a spear phishing campaign containing a new malware dubbed ‘BabyShark’. Researchers noted that the spear phishing campaign targets national security think tanks and research institutions in the US.
Worth noting
Why it matters - The phishing emails targeted universities and research institutes in the US.
What it reveals - Analysis of BabyShark malware revealed connections with other North Korean activities - KimJongRAT and STOLEN PENCIL campaign.
“While not conclusive, we suspect that the threat actor behind BabyShark is likely connected to the same actor who used the KimJongRAT malware family, and at least shares resources with the threat actor responsible for the STOLEN PENCIL campaign,” Researchers from Palo Alto networks said.
What's the conclusion - While most of the content used in the phishing emails were publicly available information on the internet, some content was non-public. This implies that the attacker behind the spear phishing campaign has most likely compromised someone from the US national security think tank who had access to private information.
“The threat actor behind it has a clear focus on gathering intelligence related to Northeast Asia’s national security issues. Well-crafted spear phishing emails and decoys suggest that the threat actor is well aware of the targets, and also closely monitors related community events to gather the latest intelligence,” researchers noted.
Publisher