Skip to content
Information Technology

Assessed Cyber Structure and Alignments of North Korea in 2023 – Mandiant

Mandiant 2 mins read

 

 

A recent assessment by cybersecurity experts at Mandiant reveals intriguing developments in North Korea's cyber landscape. The comprehensive analysis highlights key shifts, shared tooling, and evolving alignments among North Korean threat actors.

 

In this report, Mandiant provides insights into the changing dynamics of North Korea's cyber operations, as follows:

 

Continued Evolution of North Korea's Cyber Offensive Program

 

Mandiant's assessment indicates North Korea's commitment to using cyber intrusions for espionage, financial crimes, and power projection. The regime shows a growing determination to finance both its cyber and kinetic capabilities through cybercrime.

 

Increased Adaptability and Complexity

 

Recent operations suggest an increase in adaptability and complexity, including a cascading software supply chain attack – a first for North Korea. Notably, there is a consistent focus on blockchain and fintech targets.

 

Adaptation and Diversification of Threat Activity

 

North Korean threat groups continue to adapt, creating tailored malware for different platforms, including Linux and MacOS.

 

Blending of Cyber Postures

 

Mandiant's continuous monitoring has revealed a significant multiyear shift and blending of North Korea's cyber posture, leading to overlaps in targeting and shared tooling.

 

Historical Examples and Clustering for Attribution

 

The report emphasises the significance of historical examples and uncategorised clustering as a means to maintain visibility on separate threat groups.

 

The report illustrates the significant transformation of North Korea's cyber landscape since 2009 and notes the overlapping indicators among various organizations. This overlap highlights growing adaptability and collaboration between these threat actors, particularly following the 2020 COVID-19 pandemic.

 

The report provides insights into various North Korean threat groups and their primary areas of focus, including intelligence gathering, financial crimes, and targeting cryptocurrency industries. Mandiant observes shared tooling and an increasing level of flexibility in their approach, making it challenging for defenders to track and attribute their malicious activities.

 

Furthermore, the report identifies overlaps and shared resources among different threat groups, complicating attribution efforts. The analysis highlights the DPRK's growing interest in cryptocurrency-related activities, including ransomware, crypto-jacking, and theft, as a means to finance their operations.

 

Mandiant's experts also point out the increasing sophistication of supply chain attacks conducted by North Korean actors, such as UNC4736 and UNC4899, demonstrating a shift towards more aggressive and broader intrusions.

 

The report concludes by emphasising that while attribution may become more challenging due to these developments, shared infrastructure and tooling offer opportunities for detection and country-level attribution.

 

For more details and in-depth insights into the changing landscape of North Korea's cyber activities, you can access the full report at https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023

 

 


About us:

Mandiant is a recognised leader in dynamic cyber defence, threat intelligence and incident response services. By scaling decades of frontline experience, Mandiant helps organisations to be confident in their readiness to defend against and respond to cyber threats. Mandiant is now part of Google Cloud.

More from this category

  • Business Company News, Information Technology
  • 26/07/2024
  • 13:51
Data#3

Data#3 inducted into the Queensland Business Leaders Hall of Fame

Data#3 inducted into the Queensland Business Leaders Hall of Fame July 26, 2024; Brisbane, Australia: Leading Australian technology services and solutions provider, Data#3, is proud to announce that it has been inducted into the Queensland Business Leaders Hall of Fame. Data#3 accepted the Inductee Trophy at a dinner held at the Brisbane Convention and Exhibition Centre. The trophy was presented by The Honourable Grace Grace MP in recognition of the company’s continued excellence and outstanding innovation in providing technology solutions and services throughout Australia. Data#3 CEO and Managing Director, Brad Colledge, accepted the honour on stage at the event, and…

  • Contains:
  • Information Technology, Legal
  • 26/07/2024
  • 00:05
Law Society of NSW

Guidance for time-honoured profession to navigate an AI future

Friday, 26 July 2024 Guidance for time-honoured profession to navigate an AI future The Law Society of NSW has joined with LexisNexis, a leading…

  • Contains:
  • Information Technology
  • 25/07/2024
  • 23:10
GRAVITY Co., Ltd.

Gravity Announced Cute and Dark Puzzle Adventure ‘PIGROMANCE’ Official Launch on Steam!

- Award Winning Gameplay and Creativity from Various Global Game Awards- Now Celebrating Official Launch with 20% DiscountSEOUL, South Korea, July 25, 2024 (GLOBE NEWSWIRE) -- Global game developer and publisher Gravity announced the official release of the puzzle adventure ‘PIGROMANCE’ on Steam on July 25th.The puzzle adventure ‘PIGROMANCE’ elaborates the story of a pig born with the fate of becoming a sausage, escaping from a sausage factory to find its love. Players can enjoy solving puzzles while escaping from the Cuttingman and navigating the dangerous obstacles lurking throughout the sausage factory. ‘PIGROMANCE’ features cute chibi graphics with contrasting vibes…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.