Assessed Cyber Structure and Alignments of North Korea in 2023

2023-10-10 Mandiant

https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023

Thumbnail for Assessed Cyber Structure and Alignments of North Korea in 2023

Mandiant assesses that North Korea's cyber program has shifted toward a more flexible structure where DPRK-aligned groups share tooling, targeting, and personnel across espionage and financial operations. The report links this change to post-2020 pressures, including operators cut off during COVID-19 border restrictions and signs of self-funding through Andariel ransomware activity such as MAUI and HolyGh0st and APT43 cryptocurrency theft. It also describes task-force-like campaigns that combined APT43, TEMP.Hermit, and possibly Andariel activity around COVID-19 targeting. Mandiant warns that overlapping indicators now make DPRK attribution harder while allowing operators to move between blockchain, fintech, conventional weapons, nuclear, and intelligence collection priorities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bcac28919fa33704a01d7a9e5e3ddf3f 2023-02-15 2024-07-25
HASH 1ecd83ee7e4cfc8fed7ceb998e75b996 2017-11-14 2023-10-13
HASH 21cffaa7f9bf224ce75e264bfb16dd0d 2023-10-10 2023-10-10

Related Actors

Related Reports

« Back