Vedalia is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.
Vedalia is an Advanced Persistent Threat (APT) group attributed to North Korea, active in state-sponsored cyber espionage campaigns. It targets government and strategic sectors, employing tailored malware and persistence techniques to exfiltrate data and maintain footholds. The group's significance lies in its linkage to Pyongyang's broader cyber operations and its potential to influence geopolitical cybersecurity risk.
In September 2025, the North Korea-linked APT group Konni, also known as Kimsuky, targeted users by posing as counselors to steal data and wipe Android phones using Google Find Hub. The attacks also affected Windows…