APT38 DYEPACK Framework
2019-03-20 • spuz •
The source analyzes APT38’s DYEPACK framework and describes North Korean financially motivated operations against banks, including TP Bank, Bangladesh Bank, and Far Eastern International Bank. It says APT38 performs reconnaissance, spear phishing, and exploitation of exposed systems such as vulnerable Apache Struts2 servers before pivoting toward SWIFT infrastructure. DYEPACK is described as manipulating SWIFT-related databases with SQL, intercepting printer output, and modifying PDF evidence so fraudulent transactions are hidden from bank staff. The analysis also notes self-destruct behavior and anti-analysis checks such as probing 0.0.0.0.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2019-03-20 | 2019-03-20 | |
| [email protected] | 2019-03-20 | 2019-03-20 | |
| URL | https://www.investopedia.com/ar… | 2019-03-20 | 2019-03-20 |