全球高级持续性威胁(APT)2023年中报告

2023-07-12 Qianxin Global Advanced Persistent Threat (APT) 2023 Midyear Report

https://ti.qianxin.com/uploads/2023/07/12/%E5%85%A8%E7%90%83%E9%AB%98%E7%BA%A7%E6%8C%81%E7%BB%AD%E6%80%A7%E5%A8%81%E8%83%81%EF%BC%88APT%EF%BC%892023%E5%B9%B4%E4%B8%AD%E6%8A%A5%E5%91%8A.pdf

Attachments

全球高级持续性威胁APT2023年中报告.pdf (15 MB)

Qianxin's 2023 midyear APT report says its telemetry saw Lazarus among the foreign APT groups communicating with suspected compromised IP addresses in China during the first half of 2023. The report places Lazarus at about 6% of suspected controlled domestic IPs and notes that Lazarus, Bitter, Manlinghua, Rattlesnake, and other groups used dispersed C2 infrastructure and frequent C2 changes. It also says Kimsuky appeared in 8.8% of the public APT reports Qianxin collected and Group123 in 7.4%, putting DPRK-linked actors among the most frequently mentioned groups in that dataset. The DPRK relevance is one measured part of a broader global APT survey, not a standalone Lazarus case study.

Related Actors

Related Reports

« Back