MITRE ATT&CK⢠and the North Korean Regime-Backed Programmer
ID: 1990b47e-bdb4-5ca9-8d4f-7a44adb75b4e
STIX ID: report--1990b47e-bdb4-5ca9-8d4f-7a44adb75b4e
Feed Name: ReliaQuest Blog
Threat Score
This report analyzes a DOJ indictment and open-source evidence tying a North Korea-linked APT (commonly called the Lazarus Group) to large-scale, high-impact intrusions—including the Sony Pictures attack and the Bangladesh Bank SWIFT heist—and details their extensive reconnaissance, spearphishing lures, credential-stealing Brambul worm, FakeTLS C2 protocol, lateral movement techniques, and targeted manipulation of banking systems, while offering mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
