North Korean hackers crack DMARC to spoof emails from trusted sources

Estimated read time 2 min read



North Korean state-sponsored threat actors are abusing misconfigurations in DMARC to send convincing phishing emails and gather vital intelligence from Western targets, officials have warned.

A new joint advisory published by the US National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Department of State outlines how the hacking collective known as Kimsuky, which is believed to be strongly tied to Lazarus Group, and thus, with the North Korean government, has been spotted abusing improperly configured DMARC record policies to make it seem as if the emails are coming from legitimate sources.



Source link

You May Also Like

More From Author

+ There are no comments

Add yours