2023 Recap - Threat Actor Activity Highlights - North Korea

2023-12-15 Poly Swarm

https://blog.polyswarm.io/2023-recap-threat-actor-activity-highlights-north-korea

Thumbnail for 2023 Recap - Threat Actor Activity Highlights - North Korea

PolySwarm’s 2023 recap tracks several North Korea nexus clusters active across supply chain, cryptocurrency, and macOS intrusion activity. It ties Labyrinth Chollima/Lazarus to the 3CX supply chain compromise, cryptocurrency platform thefts involving Atomic Wallet, Alphapo and CoinsPaid, JumpCloud activity against crypto firms, LightlessCan use against a Spanish aerospace company, TeamCity exploitation, a trojanized CyberLink installer, and KandyKorn targeting blockchain engineers through Discord lures. The same source summarizes BlueNoroff/Stardust Chollima use of RustBucket and ObjCShellz, plus APT37/Ricochet Chollima use of SidLevel and RokRAT delivery through oversized LNK files. The report is useful as a year end map of DPRK linked actor aliases, target sets, and malware families rather than a single incident analysis.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c7f4aa77be7f7afe9d0665d3e705dbf… 2023-12-15 2024-12-27
HASH c9a7b42c7b29ca948160f95f017e9e9… 2023-12-15 2024-12-27
HASH 4f6690b82ca4b1f5735386729c4a041… 2023-12-15 2023-12-15

Related Actors

Related Reports

« Back