Supply chain
β Supply Chain
North Korean Stock Investment Firms Third-Party Breach (January 2021)
Primary Source βIncident Details
North Korean software supply chain attack targets stock investors. North Korean hacking group Thallium has been targeting a private stock investment messenger service in a supply chain attack, as reported this week. North Korean hacking group Thallium has targeted users of a private stock investment messenger service in a software supply chain attack, according to a report published this week. Up until now, the group mainly relied on phishing attacks , such as via Microsoft Office documents, to target its victims.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2021-01-01 Breach occurred
- 2021-01-05 Publicly disclosed