logo

Discover Activities Linked to the DPRK-nexus Intrusion Sets

ID: 8786a602-9f8b-508f-81e1-888c37b21a69

STIX ID: report--8786a602-9f8b-508f-81e1-888c37b21a69

Feed Name: Sekoia.com

Threat Score
92/100

Date Published: 2022-12-16

Date Updated: 2026-07-20

...
...

This report synthesizes open-source reporting on North Korea–linked intrusion sets in 2022, detailing persistent and evolving cyberespionage and financially motivated campaigns by groups such as Lazarus, Bluenoroff, Andariel, Kimsuky and Reaper. It documents malware families (BLINDINGCAN, Maui, AppleJeus, CloudMensis, Manuscrypt, MagicRAT), TTPs (spearphishing, BYOVD, zero‑day exploitation, geofencing, hosting C2 on public services), major cryptocurrency thefts and laundering, suspected ties to cybercriminal ecosystems, and concludes DPRK cyber activity remains sophisticated, adaptable, and a high-priority threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.