Assessed Cyber Structure and Alignments of North Korea in 2023
2023-10-10 • Mandiant •
https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023
Mandiant assesses that North Korea's cyber program has shifted toward a more flexible structure where DPRK-aligned groups share tooling, targeting, and personnel across espionage and financial operations. The report links this change to post-2020 pressures, including operators cut off during COVID-19 border restrictions and signs of self-funding through Andariel ransomware activity such as MAUI and HolyGh0st and APT43 cryptocurrency theft. It also describes task-force-like campaigns that combined APT43, TEMP.Hermit, and possibly Andariel activity around COVID-19 targeting. Mandiant warns that overlapping indicators now make DPRK attribution harder while allowing operators to move between blockchain, fintech, conventional weapons, nuclear, and intelligence collection priorities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bcac28919fa33704a01d7a9e5e3ddf3f | 2023-02-15 | 2024-07-25 |
| HASH | 1ecd83ee7e4cfc8fed7ceb998e75b996 | 2017-11-14 | 2023-10-13 |
| HASH | 21cffaa7f9bf224ce75e264bfb16dd0d | 2023-10-10 | 2023-10-10 |