ESET APT Activity Report Q2 2024–Q3 2024

2024-11-08 ESET

https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-2024-q3-2024/

Attachments

eset-apt-activity-report-q2-2024-q3-2024.pdf (1 MB)

Thumbnail for ESET APT Activity Report Q2 2024–Q3 2024

ESET says North Korea-aligned groups continued advancing regime priorities through attacks on financial and technology targets, especially where cryptocurrency businesses blur the two sectors. The DPRK section notes frequent abuse of cloud services such as Google Drive, Microsoft OneDrive, Dropbox, Yandex Disk, pCloud, GitHub, Bitbucket, and Zoho, with ScarCruft observed abusing Zoho for the first time. ESET also highlights Kimsuky use of Microsoft Management Console files, which can execute Windows commands despite their administrative appearance. The excerpt places these findings inside a broader APT review, but the relevant evidence is the DPRK use of cloud services, MMC files, and financially motivated targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0012c49fac5eab8ff1bcb7efab62cb1… 2024-11-08 2024-11-08
HASH 6174276f94219bc386bdc628ca18eae… 2024-11-08 2024-11-08
HASH aa6f6a50271a1d63896971c2759a619… 2024-11-08 2024-11-08

Related Actors

Related Reports

« Back