Navigating the LABYRINTH: An In-Depth Examination of Interactive Intrusions by a North Korean APT

2023-10-13 Crowd Strike

https://objectivebythesea.org/v6/talks/OBTS_v6_gLongo_bWiley.pdf

Attachments

OBTS_v6_gLongo_bWiley.pdf (3 MB)

Thumbnail for Navigating the LABYRINTH: An In-Depth Examination of Interactive Intrusions by a North Korean APT

LABYRINTH CHOLLIMA is presented as a prolific DPRK threat group tied to intelligence collection, currency generation, and high profile state sponsored operations. The slides describe a custom implant set across Windows, Linux, macOS, and Android, including the MataNet, Dacls, MATA, and TIEDYE modular framework with plugins for tunnels, proxies, compression, and upload. The intrusion examples focus on financial and technology organizations in late 2022 and early 2023, using social engineering, backdoored coding challenges or PDF readers, curl fetched macOS payloads, LaunchAgent and LaunchDaemon persistence, reconnaissance of AWS, shell history and SSH keys, and exfiltration staging. The material links the targeting to cryptocurrency theft and the expansion of DPRK operations into blockchain related sectors.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 55554944de78734d3ae638288f74df1… 2023-10-13 2023-10-13

Related Actors

Related Reports

« Back