APT Group NORTH KOREA HOME NORTH KOREA RUSSIA CHINE
|
Report Title (URL) |
Threat Actor(s) |
Primary Attack Vector(s) |
Threat Techniques |
Genian EDR in Action |
|
Kimsuky group |
Spear phishing (VBS-based,
Email-based 'ClickFix', |
VBScript (obfuscated),
PowerShell (obfuscated, 'ClickFix' tactic), |
Precise identification of threat flow, visibility into PowerShell execution, MITRE ATT&CK tagging, Attack Story Line, C2 communication monitoring, firewall integration, IoC updates |
|
|
APT37 Attack Campaign Impersonating |
APT37 (RedEyes, Group123) |
Spear-phishing emails |
ROKRAT (InfoStealer,
Backdoor), Wiper, Steganography, |
Detected attempts, provides visibility for proactive response |
|
Kimsuky Group's Triple Combo Attack |
Kimsuky Group |
Facebook, Email, |
JSE script, VMProtect-packed
DLL, tripservice.dll |
Machine learning detection, high visibility, threat hunting, MITRE ATT&CK integration, forensics |
|
APT37 |
Spear-phishing emails |
RoKRAT variant, Fileless
execution (PowerShell, in-memory shellcode), |
Immediate detection, attack storyline, abnormal behavior detection (XBA for cloud C2), MITRE ATT&CK |
|
|
Red Menshen (Chinese), others |
Linux server targeting |
BPFDoor Linux backdoor,
Process name randomization, |
Visually tracks behavior, enables rapid identification and response for open-source variants |
|
|
Konni APT Campaign Impersonating Korean National |
Konni APT |
Spear-phishing emails |
LNK, AutoIt scripts (Lilith
RAT), MSI packages, Scheduled |
Threat hunting, risk management, C2 communication monitoring, behavioral anomaly detection |
|
APT Attack Leveraging Martial Law Theme |
Kimsuky Group |
Spear phishing |
Malicious CPL file, DLL Side-loading
(legitimate Google Updater), |
Anomaly detection, real-time monitoring, comprehensive event collection, perfectly detected/blocked CPL files/C2 comms |
|
APT37 |
Spear phishing, K messenger
group chats |
HWP (OLE exploitation), LNK,
RoKRAT |
Detects abnormal HWP behavior, real-time threat notifications, XBA rules for fileless RoKRAT/C2 |
|
|
Kimsuky Group (TA406) |
Email phishing |
Primarily credential theft
via phishing sites; some |
Security rules (IoC registration), access history query, policy management, user notification |
|
|
APT37 |
Spear phishing (LNK), |
RoKRAT |
Detects fileless intermediate flows, anomalous behavior, IoC patterns, event analysis |
|
|
Kimsuky Group |
Spear phishing |
LNK, ISO, MSC, HWP (OLE
data), 'VbsEdit' abuse |
Anomaly detection, identifies MSC execution, detects HWP via IoC/XBA rules, selective threat response |
|
|
Konni (linked to Kimsuky) |
Spear phishing |
LNK, EXE, SCR, multi-stage
script obfuscation, AES CTR encryption, |
Early detection of LNK anomalies, detailed threat info, attack storyline, AMSI event summary, custom dashboards |
|
|
Konni APT (linked to Kimsuky) |
Spear phishing emails |
Malicious LNK (PowerShell,
decoy HWP), AutoIt scripts |
Detects abnormal AutoIt behavior, collects command line, identifies threat elements, displays C2 info, attack storylines, TOP 10 abnormal activities |
|
|
Kimsuky APT Attack Impersonating Foreign Media Correspondent |
Kimsuky APT, Mustang Panda |
Spear phishing |
HWP (OLE, batch file,
anti-malware check, VBScript, scheduled task), |
Effective in early detection/response for MSC, collects command line/event processes, XBA rules for abnormal behavior, forced termination, sample collection |
|
Kimsuky APT Group's New Attack Strategy |
Kimsuky APT |
Fake Facebook accounts,
Messenger |
Malicious.msc file (executed
by mmc.exe), VBScript ('warm.vbs') |
High visibility into.msc command line, behavioral detection, script/HTA anomaly detection, C2 network communication detection |
|
TutorialRAT and XenoRAT. |
Spear-phishing with malicious
LNK files |
TutorialRAT (TutRAT) - C#
based RAT, XenoRAT, Multi-stage payload delivery |
Detects these threats through behavioral analysis, identifying suspicious PowerShell commands and Dropbox API communication. |
|
|
APT37 |
Spear-phishing via email |
RoKRAT variant (fileless,
in-memory, info collection, exfiltration via pCloud API), |
Early detection (LNK, XBA rules), detects network comms, identifies fileless RoKRAT, comprehensive response, validation via simulation |
|
|
Konni APT |
Spear phishing via email |
Malicious LNK (obfuscated
PowerShell, CAB extraction, VBS/BAT |
Early detection of abnormal behavior, immediate detection of PowerShell/batch, IoC-based diagnosis, attack storyline, C2 comms confirmation |
|
|
Nation-State APT Attack Leveraging New Year's Column |
"fox tian" |
Spear-phishing email |
Malicious LNK (PowerShell,
Base64 decode), Scheduled task for |
Detects abnormal PowerShell network connections (XBA), decoy file creation, XenoRAT C2 comms |
|
APT37 (ROKRAT) |
Spear phishing |
Malicious LNK (long
command-line, hidden spaces, replaces with decoy PDF), |
Early detection of abnormal LNK, immediate detection of network comms, threat monitoring/analysis, proactive response |
|
|
APT37 Attacks Disguised as "North Korean Market Price |
APT37 |
LNK, HWP, HWPX, XLSX, DOCX
files |
Malicious OLE insertions (connects to C2, calls exploit) |
Detects APT37 activities, limits impact, required for unknown vulnerability attacks, rapid threat identification |
|
Kimsuky APT |
Malicious OLE insertions in
HWP documents |
"FlowerPower" series tools, encrypted PowerShell commands, GitHub as C2 |
Secures threat visibility, early detection to minimize damage, proactively identifies threats |
|
|
Kimsuky APT Group's "Storm Operation" and BabyShark |
Kimsuky APT |
Two-track spear phishing |
CHM, LNK, MS Word.doc with
macros, Remote template injection, |
Utility in responding to/preventing fileless attacks, provides proactive threat intelligence |
|
Kimsuky Group |
Spear phishing emails |
Malicious CHM files (execute VBS/JSE scripts embedded in HTML) |
||
|
Konni APT Campaign Targeting Unification and North |
Konni group |
Spear phishing (ZIP attachments with LNK) |
Malicious LNK (leak computer info, VBS/BAT call obfuscated scripts) |
Provides visibility into infiltration/threat activities, effective in analyzing fileless, enables early detection of abnormal behavior |
|
APT37 |
Email phishing (mimics
legitimate program, lures to |
Browser In The Browser (BitB)
technique (manipulated pop-up window |
GSC identified/analyzed, informs users/enhances products, highlights GSC's threat hunting |
|
|
Attackers exploiting |
Phishing emails or phishing sites |
AsyncRAT (open-source.NET RAT, misused for info theft/system control) |
EDR used to track, GSC conducts threat case analysis to respond to evolving TTPs |
|
|
Konni APT Campaign Disguised as National Tax |
Konni APT |
Spear phishing (ZIP with LNK and decoy HWP) |
Malicious LNK (collects/exfiltrates
info, multi-stage VBS/BAT/Powershell), |
GSC identified new activity, tracks/observes, detects complex abnormal terminal behaviors early, provides visibility, enables rapid response |
|
LockBit ransomware |
Phishing emails with
malicious IMG files |
Hidden LNK, BAT, VBS, 7z.exe,
Autologon.exe, LockBit ransomware; Multi-stage |
Detects/responds to complex, multi-stage threats, detects key events in early stages, threat event query, visual storyline |
|
|
APT37 |
Two-stage APT: initial
phishing for password/recon |
Malicious AppleScript (OSA
standard) for info collection, Staged |
Genian EDR macOS agent detects abnormal behavior early, facilitates rapid response, blocks new threats |
|