Tracking Threat Actors: How Infrastructure Analysis Reveals Cyber Attack Patterns
2025-03-05 • Kudelski Security •
Kudelski Security uses infrastructure analysis to show how analysts can cluster and revisit adversary networks over time, with a DPRK-relevant case study based on leaked North Korean IT worker PuTTY configuration data. The reconstructed infrastructure is assessed as possibly part of a wider network, potentially linked to Kaesong and ZTE references, although the article stresses that the purpose and exact North Korea relationship remain uncertain. The report recommends tagging uncertain infrastructure with explicit confidence levels, preserving historical DNS and telemetry pivots, and updating clusters as new overlaps appear. It also uses Lazarus as an example of how activity matrices can organize operators, operations, and infrastructure while warning that vendor naming conventions and attribution boundaries differ across intelligence sources.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://gopivot.ing/map/ | 2025-03-05 | 2025-03-05 |
| URL | https://gopivot.ing/ | 2025-03-05 | 2025-03-05 |
| DOMAIN | hopers.ru | 2025-03-05 | 2025-03-05 |
| DOMAIN | gopivot.ing | 2025-03-05 | 2025-03-05 |
| IPv4 | 206.71.148.78 | 2025-03-05 | 2025-03-05 |
| URL | https://cyb3rops.medium.com/the… | 2024-10-08 | 2025-03-05 |
| DOMAIN | cyb3rops.medium.com | 2024-10-08 | 2025-03-05 |