logo

MITRE ATT&CK™ and the North Korean Regime-Backed Programmer

ID: 1990b47e-bdb4-5ca9-8d4f-7a44adb75b4e

STIX ID: report--1990b47e-bdb4-5ca9-8d4f-7a44adb75b4e

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2018-09-13

Date Updated: 2026-04-29

...
...

This report analyzes a DOJ indictment and open-source evidence tying a North Korea-linked APT (commonly called the Lazarus Group) to large-scale, high-impact intrusions—including the Sony Pictures attack and the Bangladesh Bank SWIFT heist—and details their extensive reconnaissance, spearphishing lures, credential-stealing Brambul worm, FakeTLS C2 protocol, lateral movement techniques, and targeted manipulation of banking systems, while offering mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.