logo

Sanctioned North Korean unit tried to hack at least 3 US organizations this summer

ID: 798ccd17-748e-5a7b-a84d-be47c08d8914

STIX ID: report--798ccd17-748e-5a7b-a84d-be47c08d8914

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2024-10-02

Date Updated: 2026-05-01

...
...

Symantec reports that North Korean APT45 (Andariel/Stonefly) carried out intrusions against at least three U.S. private organizations in August, employing custom malware and forged certificates (including a fake Tableau certificate) with indicators matching Microsoft’s recent findings; the activity appears financially motivated (extortion) but ransomware was not successfully deployed, and operations have continued despite sanctions and an indictment of an alleged member.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.