Threat profile - North Korea
2023-04-02 • Huntandhackett •
In 2021, North Korea reportedly stole 400 million dollars from crypto exchanges.[10] Arguably one of the largest cyber-attacks that has been attributed to North Korea’s Lazarus Group is the WannaCry ransomware attack In 2017.[11] The ransomware hit over 200,000 computers across 150 countries and resulted in an estimated loss of 4 billion dollars. The attack has been linked to APT38, which is assessed to be a subgroup of the state-sponsored North Korean Lazarus group responsible for providing funds to the regime. Furthermore, North Korea is the only nation state that targets crypto exchanges to obtain funding for its regime (see case 2). Next to that, North Korea conducts targeted cyberespionage operations on sectors that contain IP and advanced knowledge on technologies useful to modernizing its key industries and to further develop its nuclear and ballistic missile programs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.weforum.org/agenda/… | 2023-04-02 | 2023-04-02 |
| URL | https://www.carscoops.com/2022/… | 2023-04-02 | 2023-04-02 |
| DOMAIN | en.setopati.com | 2023-04-02 | 2023-04-02 |