logo

North Korea's 'Stonefly' APT Swarms US Private Co's. for Profit

ID: e948e5c9-5e0f-5982-a2fb-2fcc3096e5c7

STIX ID: report--e948e5c9-5e0f-5982-a2fb-2fcc3096e5c7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-10-02

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Stonefly, a North Korean APT linked to the Reconnaissance General Bureau, has pivoted toward financially motivated intrusions against U.S. private companies; Symantec observed August compromises that deployed custom backdoors (Backdoor.Preft/Dtrack/Valefor), Nukebot, credential theft tools (Mimikatz, keyloggers), and offensive frameworks (Sliver), and used unique certificates and other IoCs—ransomware was likely the intended endgame but was not executed in the observed cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.