logo

Mapping MITRE ATT&CK to the DPRK Financial Crime Indictment

ID: 22b8d088-11e7-55d5-b639-27365c3412e1

STIX ID: report--22b8d088-11e7-55d5-b639-27365c3412e1

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2021-03-09

Date Updated: 2026-04-29

...
...

This report maps a US Department of Justice indictment of alleged DPRK-linked Lazarus Group actors to MITRE ATT&CK, concentrating on 2015–2019 financially-motivated campaigns that attempted to steal over $1.3 billion from global banks. It details reconnaissance, spear-phishing initial access, user-executed malicious files, defense evasion by masquerading, account discovery and lateral movement to compromise SWIFT endpoints, and highlights the use of custom malware (e.g., Brambul) and ransomware in these operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.