Blurred Lines of Cyber Threat Attribution: The Evolving Tactics of North Korean Cyber Threat Actors
2026-04-07 • Zscaler •
https://www.dailysecu.com/form/html/k-cti/pdf/2026/down-B-1.pdf
Attachments
down-B-1.pdf (4 MB)
Zscaler ThreatLabZ frames North Korean cyber attribution as increasingly difficult because Lazarus and Kimsuky have evolved into umbrella structures with specialized sub-clusters, shared tooling, and overlapping infrastructure. The material traces Lazarus from early activity through Sony Pictures, WannaCry, AppleJeus, ThreatNeedle, Bookcode, DeathNote, and later clusters, while describing Kimsuky-linked tooling such as BabyShark, AppleSeed, httpSpy, FPSpy, MillionOK, and AiTM phishing kits. Case studies highlight hybrid intrusions where Andariel and Kimsuky appear to contribute different phases, including supply-chain delivery through a legitimate security product, Durian Golang RAT activity, HazyLoad proxy tooling, ngrok, account manipulation, and Chrome Remote Desktop deployment. The report also uses PEBBLEDASH-related research to show how code reuse, C2 overlap, and shifting personnel can blur Lazarus-versus-Kimsuky attribution, making TTP-based clustering more reliable than single indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://buly.kr/uTnE2J | 2025-08-10 | 2026-04-07 |
| URL | https://buly.kr/FLXvf9J | 2025-08-10 | 2026-04-07 |
| URL | http://address.linkedin.p-e.kr/… | 2025-08-10 | 2026-04-07 |
| URL | https://buly.kr/ESy8l3Z | 2025-08-10 | 2026-04-07 |
| DOMAIN | buly.kr | 2025-08-10 | 2026-04-07 |
| DOMAIN | address.linkedin.p-e.kr | 2025-08-10 | 2026-04-07 |
| DOMAIN | secure.naverdomain.r-e.kr | 2025-08-10 | 2026-04-07 |
| URL | http://gsegse.dasfesfgsegsefsed… | 2025-05-19 | 2026-04-07 |
| DOMAIN | gsegse.dasfesfgsegsefsede.o-r.kr | 2025-05-15 | 2026-04-07 |
| URL | http://gtfydu.surfnet.ca/index.… | 2025-04-11 | 2026-04-07 |
| DOMAIN | gtfydu.surfnet.ca | 2025-04-11 | 2026-04-07 |
| HASH | ca93591a9441a2ade70821f67292d982 | 2025-03-04 | 2026-04-07 |
| HASH | 9e94126e8a26efd10b2a5b179d64be90 | 2025-03-04 | 2026-04-07 |