Skip to content
Information Technology

Assessed Cyber Structure and Alignments of North Korea in 2023 – Mandiant

Mandiant 2 mins read

 

 

A recent assessment by cybersecurity experts at Mandiant reveals intriguing developments in North Korea's cyber landscape. The comprehensive analysis highlights key shifts, shared tooling, and evolving alignments among North Korean threat actors.

 

In this report, Mandiant provides insights into the changing dynamics of North Korea's cyber operations, as follows:

 

Continued Evolution of North Korea's Cyber Offensive Program

 

Mandiant's assessment indicates North Korea's commitment to using cyber intrusions for espionage, financial crimes, and power projection. The regime shows a growing determination to finance both its cyber and kinetic capabilities through cybercrime.

 

Increased Adaptability and Complexity

 

Recent operations suggest an increase in adaptability and complexity, including a cascading software supply chain attack – a first for North Korea. Notably, there is a consistent focus on blockchain and fintech targets.

 

Adaptation and Diversification of Threat Activity

 

North Korean threat groups continue to adapt, creating tailored malware for different platforms, including Linux and MacOS.

 

Blending of Cyber Postures

 

Mandiant's continuous monitoring has revealed a significant multiyear shift and blending of North Korea's cyber posture, leading to overlaps in targeting and shared tooling.

 

Historical Examples and Clustering for Attribution

 

The report emphasises the significance of historical examples and uncategorised clustering as a means to maintain visibility on separate threat groups.

 

The report illustrates the significant transformation of North Korea's cyber landscape since 2009 and notes the overlapping indicators among various organizations. This overlap highlights growing adaptability and collaboration between these threat actors, particularly following the 2020 COVID-19 pandemic.

 

The report provides insights into various North Korean threat groups and their primary areas of focus, including intelligence gathering, financial crimes, and targeting cryptocurrency industries. Mandiant observes shared tooling and an increasing level of flexibility in their approach, making it challenging for defenders to track and attribute their malicious activities.

 

Furthermore, the report identifies overlaps and shared resources among different threat groups, complicating attribution efforts. The analysis highlights the DPRK's growing interest in cryptocurrency-related activities, including ransomware, crypto-jacking, and theft, as a means to finance their operations.

 

Mandiant's experts also point out the increasing sophistication of supply chain attacks conducted by North Korean actors, such as UNC4736 and UNC4899, demonstrating a shift towards more aggressive and broader intrusions.

 

The report concludes by emphasising that while attribution may become more challenging due to these developments, shared infrastructure and tooling offer opportunities for detection and country-level attribution.

 

For more details and in-depth insights into the changing landscape of North Korea's cyber activities, you can access the full report at https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023

 

 


About us:

Mandiant is a recognised leader in dynamic cyber defence, threat intelligence and incident response services. By scaling decades of frontline experience, Mandiant helps organisations to be confident in their readiness to defend against and respond to cyber threats. Mandiant is now part of Google Cloud.

More from this category

  • Games Gaming, Information Technology
  • 13/03/2026
  • 15:40
ASUS Australia

ASUS Republic of Gamers Announces New Strix OLED XG27ACDMS, and XG27AQDMES Monitors

Key Facts: 27″ Strix XG27ACDMS, and XG27AQDMES make elite OLED performance and breathtaking visuals available to a wider audience OLED Care Pro features include…

  • Contains:
  • Information Technology
  • 13/03/2026
  • 12:38
Vertiv ANZ

Vertiv Introduces Industrial-Grade UPS Designed for Commercial and Industrial Environments

Vertiv Introduces Industrial-Grade UPS Designed for Commercial and Industrial Environments Vertiv™ PowerUPS 6000 Industrial uninterruptible power supply (UPS) delivers reliable power protection for mission-critical operations across demanding industrial environments Sydney Australia, [March 13, 2026] – Vertiv (NYSE: VRT), a global leader in critical digital infrastructure, today announced the Vertiv™ PowerUPS 6000 Industrial uninterruptible power supply (UPS) system, designed to deliver reliable power protection for commercial and industrial (C&I) markets. The solution supports operations for industries including manufacturing, transportation, oil and gas, pharmaceuticals, food and beverage, packaging, and steel. “Industrial environments can face electrical instability, high temperatures, and airborne contaminants that…

  • Information Technology
  • 12/03/2026
  • 22:41
EarthDaily Analytics

EarthDaily Achieves CEOS Analysis Ready Data (CEOS-ARD) Compliance

Validation Confirms Science-Grade Integrity of the EarthDaily ConstellationVANCOUVER, British Columbia and NEW YORK, March 12, 2026 (GLOBE NEWSWIRE) -- EarthDaily today announced that its data products have achieved CEOS Analysis Ready Data (CEOS-ARD) compliance, a globally recognized standard established by the Committee on Earth Observation Satellites (CEOS).CEOS-ARD compliance confirms that EarthDaily data meet rigorous international requirements for radiometric calibration and geometric correction approaches, metadata completeness, and interoperability across time and datasets, enabling immediate quantitative analysis with minimal additional user processing.Importantly, EarthDaily achieved CEOS-ARD compliance prior to full commercial availability of its complete constellation, a rare milestone for a commercial Earth…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.