A Deep Dive into the Digital Weapons of the North Korean Cyber Army

2017-08-24 Ashley Shen

http://gsec.hitb.org/materials/sg2017/D1%20-%20Ashley%20Shen%20and%20Moonbeom%20Park%20-%20A%20Deep%20Dive%20into%20the%20Digital%20Weapons%20of%20the%20North%20Korean%20Cyber%20Army.pdf

Attachments

A_Deep_Dive_into_the_Digital_Weapons_of_the_North_Korean_Cyber_Army.pdf (24 MB)

Thumbnail for A Deep Dive into the Digital Weapons of the North Korean Cyber Army

Ashley Shen and Moonbeom Park's HITB slide deck surveys North Korean cyber operations across Lazarus, Bluenoroff, and Andariel, framing DPRK activity around social disruption, financial theft, and intelligence collection. It highlights reused malware “lego” code and case studies including Trojan Alphanc, Rifdoor/Rifle, Phandoor, GhostRAT, DesertWolf, and VANATM. The deck describes delivery through software vulnerabilities, watering-hole compromises, spear-phishing, HWP exploit documents, and malicious Office macros, with examples tied to South Korean organizations, financial targets, ATM infrastructure, and Bitcoin companies. It includes concrete C2 and malware artifacts, such as Alphanc C2 IPs and an AsdfDoor download URL/hash, to show how shared tooling links DPRK campaigns.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 220.132.191.110 2016-07-28 2017-12-12
HASH 7caa500b60a536d7501e7a6c02408538 2017-08-24 2017-08-24
URL http://wonik.com/data/file/s10/… 2017-08-24 2017-08-24
DOMAIN wonik.com 2017-08-24 2017-08-24
IPv4 202.137.244.198 2016-07-28 2016-07-28
IPv4 190.185.124.125 2016-07-28 2016-07-28

Related Reports

« Back