Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company
2023-08-07 • Sentinel One •
SentinelLabs identified North Korea-related compromise of NPO Mashinostroyeniya, a sanctioned Russian missile and military spacecraft engineering organization with sensitive missile technology. The investigation found two activity clusters: a Lazarus Group OpenCarrot Windows backdoor inside the internal network and a ScarCruft-linked compromise of a public Linux email server beaconing to external infrastructure. OpenCarrot supported broad backdoor functions including reconnaissance, file and process manipulation, DLL injection, timestomping, C2 reconfiguration, and proxying communications through internal hosts. The ScarCruft cluster could not be tied to a confirmed initial access method, but its loading tools and infrastructure resembled activity previously associated with RokRAT. The case matters because it shows multiple DPRK-affiliated threat actors targeting the same high-value Russian defense organization and raises questions about shared access, infrastructure, or parallel tasking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 99fd2e013b3fba1d03a574a24a735a82 | 2023-08-07 | 2023-08-07 |
| HASH | 6ad6232bcf4cef9bf40cbcae8ed2f985 | 2023-08-07 | 2023-08-07 |
| HASH | f483c33acf0f2957da14ed422377387… | 2023-08-07 | 2023-08-07 |
| HASH | d0f6cf0d54cf77e957bce6dfbbd34d8e | 2023-08-07 | 2023-08-07 |
| HASH | 8b6ffa56ca5bea5b406d6d8d6ef532b… | 2023-08-07 | 2023-08-07 |
| HASH | 516beb7da7f2a8b85cb170570545da4b | 2023-08-07 | 2023-08-07 |
| HASH | 07b494575d548a83f0812ceba6b8d56… | 2023-08-07 | 2023-08-07 |
| HASH | 921aa3783644750890b9d30843253ec6 | 2023-08-07 | 2023-08-07 |
| HASH | 90f52b6d077d508a23214047e680dde… | 2023-08-07 | 2023-08-07 |
| HASH | 246018220a4f4f3d20262b7333caf32… | 2023-08-07 | 2023-08-07 |
| HASH | 0b7dad90ecc731523e2eb7d682063a49 | 2023-08-07 | 2023-08-07 |
| HASH | f974d22f74b0a105668c72dc100d1d9… | 2023-08-07 | 2023-08-07 |
| HASH | 2217c29e5d5ccfcf58d2b6d9f5e250b… | 2023-08-07 | 2023-08-07 |
| HASH | 9216198a2ebc14dd68386738c1c59792 | 2023-08-07 | 2023-08-07 |
| DOMAIN | vpk.npomash.ru | 2023-08-07 | 2023-08-07 |
| DOMAIN | 606qipai.com | 2023-08-07 | 2023-08-07 |
| DOMAIN | yolenny.com | 2023-08-07 | 2023-08-07 |
| DOMAIN | redhat-packages.com | 2023-08-07 | 2023-08-07 |
| DOMAIN | bsef.or.kr | 2023-08-07 | 2023-08-07 |
| DOMAIN | asplinc.com | 2023-08-07 | 2023-08-07 |
| DOMAIN | centos-packages.com | 2023-08-07 | 2023-08-07 |
| IPv4 | 160.202.79.226 | 2023-08-07 | 2023-08-07 |
| IPv4 | 96.9.255.150 | 2023-08-07 | 2023-08-07 |
| IPv4 | 192.169.7.197 | 2023-08-07 | 2023-08-07 |
| IPv4 | 185.24.244.11 | 2023-08-07 | 2023-08-07 |
| IPv4 | 5.134.119.142 | 2023-08-07 | 2023-08-07 |
| DOMAIN | centos-pkg.org | 2023-07-12 | 2023-08-07 |
| DOMAIN | centos-repos.org | 2023-07-12 | 2023-08-07 |