North Korean hackers spotted using new tools on employees of 'nuclear-related' org
ID: c31134d0-d460-5c4c-805e-d4c979753473
STIX ID: report--c31134d0-d460-5c4c-805e-d4c979753473
Feed Name: The Record from Recorded Future News
North Korean state-backed hackers (Lazarus Group and Andariel) conducted targeted intrusion attempts against employees of a nuclear-related organization using trojanized VNC lures and a multi-stage malware chain—including CookieTime and the newly observed modular CookiePlus—while Andariel employed SmallTiger to exploit asset-management and document consolidation software; the activity demonstrates evolved delivery, persistence, and modular capabilities and is contextualized by significant cryptocurrency theft attributed to North Korean-linked actors in 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
