Microsoft sued a North Korea-linked cyber espionage group tracked as Thallium for hacking into its customers’ accounts and networks via spear-phishing attacks. The hackers target Microsoft users impersonating the company, according to a lawsuit unsealed Dec. 27 in the U.S. District Court for the Eastern District of Virginia
The group is charges of violations of the Computer Fraud & Abuse Act and Electronic Communications Privacy Act; federal trademark infringement, dilution, and false designation of origin; cybersquatting; common law trespass to chattels; unjust enrichment; conversion; intentional interference with contracts.
The Thallium APT group aimed at stealing sensitive accounts from Microsoft accounts.
Thallium cyberespionage group targets government employees, university staff members, human rights organizations, and individuals and organizations working on nuclear proliferation issues.
The APT group has been active since at least 2010, Microsoft revealed that the hackers launched spear-phishing using legitimate services, including Gmail, Yahoo, and Hotmail.
“Plaintiff MICROSOFT CORP. (“Microsoft”) hereby complains and alleges that JOHN DOES 1-2 (collectively “Defendants”), have established an Internet-based cybertheft operation referred to as “Thallium.” Through Thallium. Defendants are engaged in breaking into the Microsoft accounts and computer networks of Microsoft’s customers and stealing highly sensitive information.” reads the complaint.
“To manage and direct Thallium, Defendants have established and operate a network of websites, domains, and computers on the Internet, which they use to target their victims, compromise their online accounts, infect their computing devices, compromise the security of their networks, and steal sensitive information from them.”
Thallium uses a technique where victims after clicking on the malicious link included in the spear-phishing messages are redirected to a legitimate Microsoft domain. With this trick, attackers attempt to deceive the victims and let them into thinking the “link is not compromised because the domain is Microsoft’s and incorporates Microsoft’s trademarks.”
The Thallium cyberespionage group also uses malware to steal sensitive data from its targets, according to the complaint two of the most common malware implants used by the APT group are tracked as ‘BabyShark‘ and ‘KimJongRAT.’
“The Thallium defendants use misleading domains and Microsoft’s trademarks to cause victims to click on the links that result in installation of this malware on the victims’ computers,” continues Microsoft.
“Once installed on a victim’s computer, this malware exfiltrates information from the victim computer, maintains a persistent presence on the victim computer, and waits for further instructions from the Thallium.”
Bloomberg Law published a list of 50 domains used by Thallium in its cyber espionage campaigns and reported in Appendix A of Microsoft’s complaint against the threat actors.
The activity of the Thallium APT group was also monitored by experts from Netscout’s ATLAS Security Engineering & Response Team (ASERT) that tracked it as STOLEN PENCIL.
ASERT observed the group targeting academic institutions with spear-phishing messages containing a link to a website where a decoy document that attempts to trick users into installing a malicious Google Chrome extension. Most of the victims were at multiple universities with significant expertise in biomedical engineering.
Attackers were ensuring persistence using off-the-shelf tools, but according to NetScout, they had poor OPSEC (i.e. Korean keyboards, open web browsers in Korean, English-to-Korean translators).
This isn’t the first time Microsoft sued threat actors, in July 2017 the company used the lawsuit to disrupt a large number of cyber espionage campaigns conducted by the infamous Fancy Bear APT hacking group.
In March 2019, Microsoft announced that it had taken control of 99 domains used by an Iran-linked APT group tracked by the company as Phosphorus.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Thallium, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…
This website uses cookies.