Threat Trend Report on APT Groups – June 2023

2023-08-16 Ahnlab

https://asec.ahnlab.com/wp-content/uploads/2023/08/ATIP_2023_Jun_Threat-Trend-Report-on-APT-Groups.pdf

Attachments

ATIP_2023_Jun_Threat-Trend-Report-on-APT-Groups.pdf (254 KB)

Thumbnail for Threat Trend Report on APT Groups – June 2023

AhnLab’s June 2023 APT trend report reviews public reporting on multiple nation-state groups and includes several DPRK-relevant sections such as Andariel, Kimsuky, Lazarus, and Red Eyes/APT37. In the available excerpt, the Andariel section notes active exploitation of Log4j and the addition of malware families such as YamaBot and MagicRat, with commercial tools including 3Proxy, Dumpert, ForkDump, Powerline, PuTTY, NTDSDumpEx, and Supremo also observed. The same excerpt notes that EarlyRat infrastructure overlapped with servers used in the HolyGhost and Maui ransomware campaigns. Because this is a broad multi-actor report, the summary should be read as a DPRK-focused extraction rather than coverage of every APT group in the PDF.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bab695345e984edbb8fe5e16e36face6 2023-08-16 2023-08-16

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back