Sangria Tempest is an advanced persistent threat (APT) that has been active since at least 2015, targeting government and military organizations in South Korea. It is believed to be linked to North Korean hackers who are part of the Lazarus Group. Sangria Tempest uses a variety of tactics such as spear-phishing emails, watering hole attacks, and malware downloads from compromised websites to gain access to its targets\' networks. Once inside, it steals sensitive information like military plans or financial data for extortion purposes.
Techniques, tactics and practices:
Sangria Tempest uses a variety of tactics such as spear-phishing emails, watering hole attacks, and malware downloads from compromised websites to gain access to its targets\' networks. Once inside, it steals sensitive information like military plans or financial data for extortion purposes.
