Google's Threat Analysis Group said a North Korean government-backed actor continued a campaign against security researchers by creating a fake offensive security company, SecuriElite, and associated social media profiles to build credibility and lure targets. The operation followed earlier activity in which the attackers used a PGP key posted on an attacker-controlled blog to entice researchers to visit a website where a browser exploit would be triggered, and Google added the new SecuriElite site to Safe Browsing as a precaution even though it had not yet been seen serving malicious content.
The campaign was linked by researchers to exploitation of an Internet Explorer zero-day, reinforcing concerns that the group maintains access to multiple previously unknown vulnerabilities. Google warned that the operators likely possess additional zero-days, underscoring the risk to vulnerability researchers and offensive security professionals who may be approached through seemingly legitimate research collaboration or recruiting outreach.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On March 17, 2021, the actors created a fake offensive security company called SecuriElite, along with a website and associated social media profiles, to continue social engineering against security researchers. The site claimed the company was based in Turkey and advertised pentests, software security assessments, and exploits.
Following Google's January blog post, security researchers identified the actors as using an Internet Explorer zero-day. Google also warned that the group likely possesses additional zero-days.
Google Threat Analysis Group said it had previously documented a campaign targeting security researchers in January 2021. In the March update, Google attributed the activity to a North Korean government-backed entity.
Google identified LinkedIn accounts impersonating recruiters for antivirus and security companies and reported the social media profiles to the relevant platforms. Google also added the new SecuriElite website to Safe Browsing as a precaution, while noting it had not yet observed the site serving malicious content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.