  • Also known as Thallium, Smoke Screen, Emerald Sleet, TA-406, Sharptongue, Black Banshee, and APT43.
This threat actor targeted foreign ministries and think tanks in Europe and the United States using malware hidden in Microsoft Word documents and antiquated file formats.
Suspected victims
  • France
  • U.S. Think Tanks
  • Slovakia
  • UK Think Tanks
  • Stanford University
Suspected state sponsor
  • Korea (Democratic People's Republic of)
Target category
  • Government
  • Private sector