Supply chain β›“ Supply Chain

North Korean Stock Investment Firms Third-Party Breach (January 2021)

πŸ“… 2021-01-01 🏒 Not disclosed
Primary Source β†—

Incident Details

North Korean software supply chain attack targets stock investors. North Korean hacking group Thallium has been targeting a private stock investment messenger service in a supply chain attack, as reported this week. North Korean hacking group Thallium has targeted users of a private stock investment messenger service in a software supply chain attack, according to a report published this week. Up until now, the group mainly relied on phishing attacks , such as via Microsoft Office documents, to target its victims.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Not disclosed
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-01-01 Breach occurred
  2. 2021-01-05 Publicly disclosed