Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Proofpoint reported a December 2022 TA444-linked campaign that used OneDrive-themed phishing to steal credentials, rather than relying only on the malware-delivery methods it had previously observed. The emails targeted people in the United States and Canada across several sectors. Proofpoint assessed the attribution as moderate to moderately high, but said it could not rule out another actor using compromised TA444 infrastructure.

What changed in the reported attacks?

Proofpoint’s January 25, 2023 report described a shift in observed delivery activity. During 2022, the company had seen TA444 use LNK-oriented delivery and remote-template documents, while also experimenting with other file types. In early December, Proofpoint instead observed a OneDrive-themed email campaign that led recipients to a credential-harvesting page. This is evidence of a different technique in that campaign—not proof that TA444 permanently changed its strategy.

Proofpoint tracks TA444 as a North Korean state-sponsored actor associated with financially motivated operations and cryptocurrency targeting. It notes overlap between TA444 and labels used by other researchers; those names should not be treated as universally interchangeable or as a definitive organizational chart. Proofpoint says the actor has targeted cryptocurrency since at least 2017.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did the December 2022 campaign work?

  1. The email presented a OneDrive-themed lure. Proofpoint reported messages sent to targets in the United States and Canada, with typos and an apparent “Admin” sender presentation.
  2. The message linked through SendGrid. The link redirected recipients toward a credential-harvesting page rather than the malware-delivery approaches Proofpoint had commonly associated with TA444.
  3. The subject imitated an invoice. Proofpoint noted a subject line using a lowercase “l” in place of the initial capital “I.” These are historical campaign details, not reliable proof that a similar-looking message is from TA444.

Who was targeted?

Proofpoint said the campaign spanned education, government, healthcare, and financial organizations in the United States and Canada. This sector and geography description applies to the campaign it observed; the report does not establish the full scope of TA444’s activity or victims.

How large was the email wave?

Proofpoint said this wave nearly doubled all TA444 messages it had observed in its own data during 2022. That comparison describes Proofpoint’s telemetry, not the total number of TA444 emails, attacks, or victims worldwide.

How certain is the attribution?

Proofpoint rated attribution moderate to moderately high, citing infrastructure it considered exclusive to TA444 and sender-domain authentication signals. The company nevertheless said it could not exclude the possibility that another actor had compromised a TA444 server. It also raised the possibility that TA444 itself was conducting different operations. The report therefore supports a qualified link to TA444, not certainty about who controlled the infrastructure or why the activity differed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does this compare with earlier activity?

Aspect Earlier activity described by Proofpoint Early December 2022 campaign
Delivery method LNK-oriented delivery and remote-template documents; experimentation with other file types during 2022. OneDrive-themed email linking through SendGrid to a credential-harvesting page.
Target scope Proofpoint associated TA444 with financially motivated operations and cryptocurrency targeting; it says cryptocurrency targeting dates to at least 2017. Targets in the United States and Canada across education, government, healthcare, and financial sectors.
Attribution evidence Not stated as a separate comparison in the report. Proofpoint cited exclusive infrastructure and sender-authentication signals, while retaining the possibility of a compromised server.

The comparison captures what Proofpoint observed, not a confirmed lasting shift in TA444’s mission or operating model. Its authors described the actor as having an “upstart mentality” in late 2022; that is their characterization of experimentation, not an independently established motive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.