TTP Tuesday: APT38 - The Sony Hack

2022-05-25 Prelude

https://feed.prelude.org/p/apt38-sony?s=r

Thumbnail for TTP Tuesday: APT38 - The Sony Hack

Prelude's TTP Tuesday article uses the 2014 Sony Pictures compromise to model APT38/Guardians of Peace tradecraft. It summarizes the operation's political trigger around The Interview, the leaking of Sony emails, employee records and unreleased films, destructive Destover malware warnings, extortion threats against the film's release, and the FBI's public attribution to North Korea. The practical content is a replayable adversary-emulation chain: maintain an agent on the victim, use registry edits for persistence, replicate process-killing behavior associated with the attack, and demonstrate how the operators combined persistence, exfiltration, destructive impact, and coercive messaging. The report is useful less as original incident reporting and more as a structured TTP exercise for defenders emulating APT38-style Sony Hack behaviors.

Related Actors

Related Reports

« Back