North Korean APT Groups

Lazarus Group (APT38)

  • Affiliation: North Korean government's Reconnaissance General Bureau

  • Activities: Known for the WannaCry ransomware attack, Sony Pictures hack, and targeting financial institutions, media organizations, aerospace, and defense industries. Active since 2009.

  • Targets: Financial institutions, media organizations, aerospace, defense industries.

  • TTPs (Tactics, Techniques, Procedures):

  • Notable Incidents:

    • WannaCry Ransomware Attack (2017): This global ransomware attack infected over 230,000 computers across 150 countries. It encrypted data and demanded ransom payments in Bitcoin. The attack caused significant disruption to various industries, including healthcare, finance, and transportation. Read morearrow-up-right

    • Sony Pictures Hack (2014): Lazarus Group launched a devastating cyber attack on Sony Pictures, leading to the leak of confidential information, including unreleased films, employee data, and email communications. The attack was motivated by the planned release of the movie "The Interview." Read morearrow-up-right

    • Operation Ghost (2013-2019): Lazarus Group targeted government networks in Europe and NATO member countries, using steganography to hide data within images. This long-running campaign involved persistent surveillance and data exfiltration. Read morearrow-up-right

Kimsuky (APT43)

Last updated