Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company

2023-08-07 Sentinel One

https://www.sentinelone.com/labs/comrades-in-arms-north-korea-compromises-sanctioned-russian-missile-engineering-company/

Thumbnail for Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company

SentinelLabs identified North Korea-related compromise of NPO Mashinostroyeniya, a sanctioned Russian missile and military spacecraft engineering organization with sensitive missile technology. The investigation found two activity clusters: a Lazarus Group OpenCarrot Windows backdoor inside the internal network and a ScarCruft-linked compromise of a public Linux email server beaconing to external infrastructure. OpenCarrot supported broad backdoor functions including reconnaissance, file and process manipulation, DLL injection, timestomping, C2 reconfiguration, and proxying communications through internal hosts. The ScarCruft cluster could not be tied to a confirmed initial access method, but its loading tools and infrastructure resembled activity previously associated with RokRAT. The case matters because it shows multiple DPRK-affiliated threat actors targeting the same high-value Russian defense organization and raises questions about shared access, infrastructure, or parallel tasking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 99fd2e013b3fba1d03a574a24a735a82 2023-08-07 2023-08-07
HASH 6ad6232bcf4cef9bf40cbcae8ed2f985 2023-08-07 2023-08-07
HASH f483c33acf0f2957da14ed422377387… 2023-08-07 2023-08-07
HASH d0f6cf0d54cf77e957bce6dfbbd34d8e 2023-08-07 2023-08-07
HASH 8b6ffa56ca5bea5b406d6d8d6ef532b… 2023-08-07 2023-08-07
HASH 516beb7da7f2a8b85cb170570545da4b 2023-08-07 2023-08-07
HASH 07b494575d548a83f0812ceba6b8d56… 2023-08-07 2023-08-07
HASH 921aa3783644750890b9d30843253ec6 2023-08-07 2023-08-07
HASH 90f52b6d077d508a23214047e680dde… 2023-08-07 2023-08-07
HASH 246018220a4f4f3d20262b7333caf32… 2023-08-07 2023-08-07
HASH 0b7dad90ecc731523e2eb7d682063a49 2023-08-07 2023-08-07
HASH f974d22f74b0a105668c72dc100d1d9… 2023-08-07 2023-08-07
HASH 2217c29e5d5ccfcf58d2b6d9f5e250b… 2023-08-07 2023-08-07
HASH 9216198a2ebc14dd68386738c1c59792 2023-08-07 2023-08-07
DOMAIN vpk.npomash.ru 2023-08-07 2023-08-07
DOMAIN 606qipai.com 2023-08-07 2023-08-07
DOMAIN yolenny.com 2023-08-07 2023-08-07
DOMAIN redhat-packages.com 2023-08-07 2023-08-07
DOMAIN bsef.or.kr 2023-08-07 2023-08-07
DOMAIN asplinc.com 2023-08-07 2023-08-07
DOMAIN centos-packages.com 2023-08-07 2023-08-07
IPv4 160.202.79.226 2023-08-07 2023-08-07
IPv4 96.9.255.150 2023-08-07 2023-08-07
IPv4 192.169.7.197 2023-08-07 2023-08-07
IPv4 185.24.244.11 2023-08-07 2023-08-07
IPv4 5.134.119.142 2023-08-07 2023-08-07
DOMAIN centos-pkg.org 2023-07-12 2023-08-07
DOMAIN centos-repos.org 2023-07-12 2023-08-07

Related Actors

Related Reports

« Back