APT ACTIVITY REPORT T3 2022

2023-01-31 ESET

https://www.welivesecurity.com/wp-content/uploads/2023/01/eset_apt_activity_report_t32022.pdf

Attachments

eset_apt_activity_report_t32022.pdf (4 MB)

Thumbnail for APT ACTIVITY REPORT T3 2022

ESET’s T3 2022 APT activity reporting notes that North Korea-aligned groups remained active against cryptocurrency firms and exchanges in multiple regions. The DPRK-linked activity relied on older exploits to compromise targets, while Kimsuky continued operations without major changes in targeting or TTPs. The report also observed Konni broadening its decoy-document language set to English, suggesting possible targeting beyond its usual Russian and Korean focus. Because the source is a broad multi-actor APT roundup, the DPRK-relevant finding is the continued targeting of cryptocurrency organizations and the persistence of established North Korea-aligned tradecraft during the period.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db9a6efd5d64ba0ba1783c51b6d4308… 2023-01-31 2023-01-31
HASH 2bc366eb7759c0c7def2b74c2e16ceb… 2023-01-31 2023-01-31
HASH a50ec84c9205116ce2515281909ab04… 2023-01-31 2023-01-31
HASH b200b34f29ea4b9b6965d7b696d07ac… 2023-01-31 2023-01-31
HASH 296599df29f4ffa9bf753ff9440032d… 2023-01-31 2023-01-31
HASH 1cffaf3be725d1514c87c328ca578d5… 2023-01-31 2023-01-31
URL https://yck1509.github.io/Confu… 2023-01-31 2023-01-31
DOMAIN simple-help.com 2023-01-31 2023-01-31
DOMAIN yck1509.github.io 2023-01-31 2023-01-31
DOMAIN blueskynetwork-shared.com 2023-01-31 2023-01-31
DOMAIN umopl-drive.com 2023-01-31 2023-01-31

Related Reports

2023-02-02 • 25% Match
#Whitepaper #NoPineapple #DTrack #GREASE #Zimbra #T1082 #T1119 #T1070.004 #T1041 #T1560 #T1071.001 #T1083 #T1071 #T1057 #T1053.005 #T1036.005 #T1059 #T1078 #T1190 #T1049 #T1016 #T1018 #T1003.001 #T1021.001 #T1106 #T1090.001 #T1074 #T1553 #T1033 #T1569.002 #T1090.002 #T1012 #T1087.002 #T1114.002 #T1505.003 #T1556 #T1037.005 #T1136 #T1070.007 #T1587.002
Shares tags: T1560, T1071, T1190 • Published within a week
« Back