ESET APT Activity Report Q2 2024–Q3 2024
2024-11-08 • ESET •
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-2024-q3-2024/
Attachments
ESET says North Korea-aligned groups continued advancing regime priorities through attacks on financial and technology targets, especially where cryptocurrency businesses blur the two sectors. The DPRK section notes frequent abuse of cloud services such as Google Drive, Microsoft OneDrive, Dropbox, Yandex Disk, pCloud, GitHub, Bitbucket, and Zoho, with ScarCruft observed abusing Zoho for the first time. ESET also highlights Kimsuky use of Microsoft Management Console files, which can execute Windows commands despite their administrative appearance. The excerpt places these findings inside a broader APT review, but the relevant evidence is the DPRK use of cloud services, MMC files, and financially motivated targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0012c49fac5eab8ff1bcb7efab62cb1… | 2024-11-08 | 2024-11-08 |
| HASH | 6174276f94219bc386bdc628ca18eae… | 2024-11-08 | 2024-11-08 |
| HASH | aa6f6a50271a1d63896971c2759a619… | 2024-11-08 | 2024-11-08 |