Threat intelligence
- Suspected origin
- North Korea
- TLP
- WHITE
A subgroup of Lazarus Group, Hidden Cobra, Labyrinth Chollima.
(Kaspersky) The Lazarus Group, a nation-state level of attacker tied to the 2014 attacks on Sony Pictures Entertainment, has splintered off a portion of its operation to concentrate on stealing money to fund itself.
Also known as
Alluring PiscesAPT 38APT38ATK 117BeagleBoyzBlack AlicantoBluenoroffCoperniciumCTG-6459G0082Nickel GladstoneSapphire SleetSelective PiscesStardust ChollimaT-APT-15TA444TAG-71TEMP.Hermit
Tooling and malware
DarkCometECCENTRICBANDWAGONHOPLIGHTKillDiskMimikatzNet
MITRE ATT&CK techniques
T1005 Data from Local SystemT1115 Clipboard DataT1105 Ingress Tool TransferT1110 Brute ForceT1112 Modify RegistryT1685 Disable or Modify ToolsT1686 Disable or Modify System FirewallT1690 Prevent Command History LoggingT1033 System Owner/User DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1135 Network Share DiscoveryT1217 Browser Information DiscoveryT1106 Native APIT1485 Data DestructionT1486 Data Encrypted for ImpactT1529 System Shutdown/RebootT1189 Drive-by CompromiseT1055 Process InjectionT1140 Deobfuscate/Decode Files or Information
Coverage 2
supply-chain
Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account…
threat-intel
A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring…
