Analysis of Attack Strategies Targeting Centralized Management Solutions
2025-01-21 • KRCERT •
KISA’s JSAC 2025 presentation describes North Korean hacking activity targeting centralized management solutions used to administer corporate devices. The speakers tie the investigation to Maui ransomware leads, attacker Google account activity, leased Korean hosting infrastructure, and search behavior that included North Korean language usage. The presentation also discusses remote-control malware management tooling and attacker interest in Korean DLP and antivirus software code as high-value paths into enterprise environments.
Related Actors
Related Reports
Shares tags: Andariel, AnOctopus • Same author: KRCERT • Published within a week
Shares tags: Andariel, AnOctopus • Same author: KRCERT
Shares tag: Andariel • Published within a week
Shares tag: Andariel • Published within a week
2025-01-20 •
53% Match
An exploratory analysis of the DPRK cyber threat landscape using publicly available reports
lazarusholic
Shares tag: Andariel • Published within a week
2025-01-02 •
53% Match
#Andariel
#Ransomware
#Play
#T1046
#T1219
#T1562.001
#T1486
#T1018
#T1657
#T1003.001
#T1048.003
#T1560.001
#T1033
#T1087.002
#T1570
#T1069.001
#T1069.002
#T1572
#T1615
#T1482
Shares tag: Andariel • Published within a month