North Korean hackers crack DMARC to spoof emails from trusted sources

North Korean state-sponsored threat actors are exploiting misconfigurations in DMARC to send convincing phishing emails and collect vital information from Western targets, officials warn.

A new joint advisory published by the US National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the State Department outlines how the hacking collective known as Kimsuky, believed to be strongly linked to the Lazarus Group, and For example, the North Korean government has been noted to be abusing misconfigured DMARC records policies to make it appear as if the emails come from legitimate sources.