North Korea's 'Stonefly' APT Swarms US Private Co's. for Profit
ID: e948e5c9-5e0f-5982-a2fb-2fcc3096e5c7
STIX ID: report--e948e5c9-5e0f-5982-a2fb-2fcc3096e5c7
Feed Name: Dark Reading
Date Published: 2024-10-02
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Stonefly, a North Korean APT linked to the Reconnaissance General Bureau, has pivoted toward financially motivated intrusions against U.S. private companies; Symantec observed August compromises that deployed custom backdoors (Backdoor.Preft/Dtrack/Valefor), Nukebot, credential theft tools (Mimikatz, keyloggers), and offensive frameworks (Sliver), and used unique certificates and other IoCs—ransomware was likely the intended endgame but was not executed in the observed cases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
