Blurred Lines of Cyber Threat Attribution: The Evolving Tactics of North Korean Cyber Threat Actors

2026-04-07 Zscaler

https://www.dailysecu.com/form/html/k-cti/pdf/2026/down-B-1.pdf

Attachments

down-B-1.pdf (4 MB)

Zscaler ThreatLabZ frames North Korean cyber attribution as increasingly difficult because Lazarus and Kimsuky have evolved into umbrella structures with specialized sub-clusters, shared tooling, and overlapping infrastructure. The material traces Lazarus from early activity through Sony Pictures, WannaCry, AppleJeus, ThreatNeedle, Bookcode, DeathNote, and later clusters, while describing Kimsuky-linked tooling such as BabyShark, AppleSeed, httpSpy, FPSpy, MillionOK, and AiTM phishing kits. Case studies highlight hybrid intrusions where Andariel and Kimsuky appear to contribute different phases, including supply-chain delivery through a legitimate security product, Durian Golang RAT activity, HazyLoad proxy tooling, ngrok, account manipulation, and Chrome Remote Desktop deployment. The report also uses PEBBLEDASH-related research to show how code reuse, C2 overlap, and shifting personnel can blur Lazarus-versus-Kimsuky attribution, making TTP-based clustering more reliable than single indicators.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://buly.kr/uTnE2J 2025-08-10 2026-04-07
URL https://buly.kr/FLXvf9J 2025-08-10 2026-04-07
URL http://address.linkedin.p-e.kr/… 2025-08-10 2026-04-07
URL https://buly.kr/ESy8l3Z 2025-08-10 2026-04-07
DOMAIN buly.kr 2025-08-10 2026-04-07
DOMAIN address.linkedin.p-e.kr 2025-08-10 2026-04-07
DOMAIN secure.naverdomain.r-e.kr 2025-08-10 2026-04-07
URL http://gsegse.dasfesfgsegsefsed… 2025-05-19 2026-04-07
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
URL http://gtfydu.surfnet.ca/index.… 2025-04-11 2026-04-07
DOMAIN gtfydu.surfnet.ca 2025-04-11 2026-04-07
HASH ca93591a9441a2ade70821f67292d982 2025-03-04 2026-04-07
HASH 9e94126e8a26efd10b2a5b179d64be90 2025-03-04 2026-04-07

Related Actors

Related Reports

« Back