Response to CISA Advisory (AA24-207A): North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
ID: 453e886d-851b-5659-b96b-5ce0e2b60ff5
STIX ID: report--453e886d-851b-5659-b96b-5ce0e2b60ff5
Feed Name: Security Boulevard
This report summarizes a multi-agency Cybersecurity Advisory on Andariel (Onyx Sleet), a DPRK RGB-associated APT subgroup conducting global espionage against defense, aerospace, nuclear and engineering sectors, detailing their tactics (web server exploitation including Log4j, web shells, phishing with LNK/HTA, scheduled tasks, credential dumping with Mimikatz, RDP lateral movement, C2, and exfiltration) and noting use of Maui ransomware to fund operations; AttackIQ provides an assessment template to emulate these post-compromise TTPs for testing detection and mitigation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
