A Deep Dive into the Digital Weapons of the North Korean Cyber Army
2017-08-24 • Ashley Shen •
Attachments
Ashley Shen and Moonbeom Park's HITB slide deck surveys North Korean cyber operations across Lazarus, Bluenoroff, and Andariel, framing DPRK activity around social disruption, financial theft, and intelligence collection. It highlights reused malware “lego” code and case studies including Trojan Alphanc, Rifdoor/Rifle, Phandoor, GhostRAT, DesertWolf, and VANATM. The deck describes delivery through software vulnerabilities, watering-hole compromises, spear-phishing, HWP exploit documents, and malicious Office macros, with examples tied to South Korean organizations, financial targets, ATM infrastructure, and Bitcoin companies. It includes concrete C2 and malware artifacts, such as Alphanc C2 IPs and an AsdfDoor download URL/hash, to show how shared tooling links DPRK campaigns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 220.132.191.110 | 2016-07-28 | 2017-12-12 |
| HASH | 7caa500b60a536d7501e7a6c02408538 | 2017-08-24 | 2017-08-24 |
| URL | http://wonik.com/data/file/s10/… | 2017-08-24 | 2017-08-24 |
| DOMAIN | wonik.com | 2017-08-24 | 2017-08-24 |
| IPv4 | 202.137.244.198 | 2016-07-28 | 2016-07-28 |
| IPv4 | 190.185.124.125 | 2016-07-28 | 2016-07-28 |