logo

North Korea APT Triumvirate Spied on South Korean Defense Industry For Years

ID: bd3cd656-9dc1-51c1-a01e-340d581d49ca

STIX ID: report--bd3cd656-9dc1-51c1-a01e-340d581d49ca

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-04-24

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

South Korean police disclosed concurrent espionage campaigns by DPRK-linked APTs Andariel, Kimsuky, and the broader Lazarus Group that infiltrated roughly 10 defense-related organizations over at least 18 months, using credential compromise, exploitation of a groupware/email vulnerability, and deployment of RATs (Nukesped, Tiger) to harvest and exfiltrate defense-related data; investigators tied malware and infrastructure (including some IPs) to prior attacks and recommended two-factor authentication, network segmentation, password rotation, and blocking unauthorized foreign IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.