North Korean threat actors
· Published 21/12/2025 04:30 · Modified 21/12/2025 04:30
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 04:30
- Modified
- 21/12/2025 04:30
- Updated at
- 21/12/2025 04:30
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 18 attack patterns (mitre), 3 malware, 6 sectors, 11 countries, 37 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
12 MITREs 2 Malwares 56 Observables 1 APTPublished 06/11/2024 11:06 · Modified 06/11/2024 11:34
-
9 MITREs 1 Malware 7 Observables 1 APTPublished 29/04/2024 18:38 · Modified 01/05/2024 23:06
Attack patterns (MITRE) (18)
-
T1070.004 usesFile Deletion
-
T1033 usesSystem Owner/User Discovery
-
T1071.002 usesFile Transfer Protocols
-
T1005 usesData from Local System
-
T1082 usesSystem Information Discovery
-
T1071.001 usesWeb Protocols
-
T1560 usesArchive Collected Data
-
T1083 usesFile and Directory Discovery
-
T1560.001 usesArchive via Utility
-
T1059.007 usesJavaScript
-
T1041 usesExfiltration Over C2 Channel
-
T1204.002 usesMalicious File
-
T1132 usesData Encoding
-
T1059.006 usesPython
-
T1059.003 usesWindows Command Shell
-
T1566.003 usesSpearphishing via Service
-
T1555.003 usesCredentials from Web Browsers
-
T1059.001 usesPowerShell
Malware (3)
-
InvisibleFerret usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
-
DEV#POPPER usesFamilyPublished 29/04/2024 18:38 · Modified 29/04/2024 18:38
-
BeaverTail usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
Sectors (6)
- Defense targets
- Retail targets
- Healthcare targets
- Finance targets
- Construction targets
- Technology targets
Countries (11)
- Estonia targets
- United States of America targets
- British Indian Ocean Territory targets
- Nigeria targets
- United Kingdom of Great Britain and Northern Ireland targets
- Russian Federation targets
- India targets
- Kenya targets
- Spain targets
- Pakistan targets
- Japan targets
Indicators (37)
-
da8e2c248dbb92e62fa3d270ac3d32e52e23827e452bab5d945dd7f3cbd9851aindicates -
bc4a082e2b999d18ef2d7de1948b2bfd9758072f5945e08798f47827686621f2indicates -
http://147.124.214.131indicates -
f3ead5405456b1d0a176c817bda8096c16a2c33df51526084fed6a4f46f9e636indicates -
6c905ea5c116aabf9328b314a1d32538206113b9a2c700e6d1490df46e65ee94indicates -
33617f0ac01a0f7fa5f64bd8edef737f678c44e677e4a2fb23c6b8a3bcd39fa2indicates -
w3capi.marketingindicates -
9e3a9dbf10793a27361b3cef4d2c87dbd3662646f4470e5242074df4cb96c6b4indicates -
24b89c77eaeebd4b02c8e8ab6ad3bd7abaa18893ecd469a6a04eda5e374dd305indicates -
977a9024962102b02128d391c0543c63328d3f26701eca1a5d282af4d493dc2eindicates -
dcde59721b78e6797ee7f79c0e19c4a1c5a7806d20cbfa4a6ebb8efca189baf3indicates -
0f5f0a3ac843df675168f82021c24180ea22f764f87f82f9f77fe8f0ba0b7132indicates -
36cac29ff3c503c2123514ea903836d5ad81067508a8e16f7947e3e675a08670indicates -
bc20cd53badb77404b2f82ea9107f7d9e9c7e4a0ebd8793a52227ea887d91ba7indicates -
0621d37818c35e2557fdd8a729e50ea662ba518df8ca61a44cc3add5c6deb3cdindicates -
d801ad1beeab3500c65434da51326d7648a3c54923d794b2411b7b6a2960f31eindicates -
bf411c4d1275136d29cb001a1521f49c67f86fe944f97ea5352d18996fce60e7indicates -
f9ca12321fb91157cce8513e935810d1c2005ab0739322b474f0cb4af2605d16indicates -
bc2a2efcb085d209e1358d2bfe57cd348c4b8f6f3f02fb0ee80e688a9ec3a318indicates -
d5c0b89e1dfbe9f5e5b2c3f745af895a36adf772f0b72a22052ae6dfa045cea6indicates -
45c991529a421104f2edf03d92e01d95774bf54325f9107dd4139505912a0c1eindicates -
d8806fb404bf29e4a3941c912cbb48553ad5340e1b7195a94e6abf8d75b9102cindicates -
b8e69d6a766b9088d650e850a638d7ab7c9f59f4e24e2bc8eac41c380876b0d8indicates -
9110515c2d5f6f48871f0631f411d55f2f0307286e6678952f5d86abe5ce11a9indicates -
b378d389fd31c6cb65fc85ea960b609049c5f97266cafcbfc6d261fa09355cc0indicates -
d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763indicates -
720df4162feaa5ca1cbf19b4d30a7b7c5ea2e0128e6a4978c448d2ccb78e5f1bindicates -
9abf6b93eafb797a3556bea1fe8a3b7311d2864d5a9a3687fce84bc1ec4a428cindicates -
regioncheck.netindicates -
000b4a77b1905cabdb59d2b576f6da1b2ef55a0258004e4a9e290e9f41fb6923indicates -
f06323e253b5dd6a2759ffd04452241c2a4020115aece5fc02da90918a53cf7bindicates -
c0110cb21ae0e7fb5dec83ca90db9e250b47a394662810f230eb621b0728aa97indicates -
fd9e8fcc5bda88870b12b47cbb1cc8775ccff285f980c4a2b683463b26e36bf0indicates -
payloadrpc.comindicates -
de6f9e9e2ce58a604fe22a9d42144191cfc90b4e0048dffcc69d696826ff7170indicates -
mirotalk.netindicates -
cd13a9c92210ada940a44769874dd6716f85c4e4e9d7323ec5789c7b253d937dindicates