APT ACTIVITY REPORT T3 2022
2023-01-31 • ESET •
https://www.welivesecurity.com/wp-content/uploads/2023/01/eset_apt_activity_report_t32022.pdf
Attachments
ESET’s T3 2022 APT activity reporting notes that North Korea-aligned groups remained active against cryptocurrency firms and exchanges in multiple regions. The DPRK-linked activity relied on older exploits to compromise targets, while Kimsuky continued operations without major changes in targeting or TTPs. The report also observed Konni broadening its decoy-document language set to English, suggesting possible targeting beyond its usual Russian and Korean focus. Because the source is a broad multi-actor APT roundup, the DPRK-relevant finding is the continued targeting of cryptocurrency organizations and the persistence of established North Korea-aligned tradecraft during the period.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | db9a6efd5d64ba0ba1783c51b6d4308… | 2023-01-31 | 2023-01-31 |
| HASH | 2bc366eb7759c0c7def2b74c2e16ceb… | 2023-01-31 | 2023-01-31 |
| HASH | a50ec84c9205116ce2515281909ab04… | 2023-01-31 | 2023-01-31 |
| HASH | b200b34f29ea4b9b6965d7b696d07ac… | 2023-01-31 | 2023-01-31 |
| HASH | 296599df29f4ffa9bf753ff9440032d… | 2023-01-31 | 2023-01-31 |
| HASH | 1cffaf3be725d1514c87c328ca578d5… | 2023-01-31 | 2023-01-31 |
| URL | https://yck1509.github.io/Confu… | 2023-01-31 | 2023-01-31 |
| DOMAIN | simple-help.com | 2023-01-31 | 2023-01-31 |
| DOMAIN | yck1509.github.io | 2023-01-31 | 2023-01-31 |
| DOMAIN | blueskynetwork-shared.com | 2023-01-31 | 2023-01-31 |
| DOMAIN | umopl-drive.com | 2023-01-31 | 2023-01-31 |