logo

North Korean hackers spotted using new tools on employees of 'nuclear-related' org

ID: c31134d0-d460-5c4c-805e-d4c979753473

STIX ID: report--c31134d0-d460-5c4c-805e-d4c979753473

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2024-12-23

Date Updated: 2026-05-01

...
...

North Korean state-backed hackers (Lazarus Group and Andariel) conducted targeted intrusion attempts against employees of a nuclear-related organization using trojanized VNC lures and a multi-stage malware chain—including CookieTime and the newly observed modular CookiePlus—while Andariel employed SmallTiger to exploit asset-management and document consolidation software; the activity demonstrates evolved delivery, persistence, and modular capabilities and is contextualized by significant cryptocurrency theft attributed to North Korean-linked actors in 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.