APT Group NORTH KOREA  HOME  NORTH KOREA  RUSSIA  CHINE


Report Title (URL)

Threat Actor(s)

Primary Attack Vector(s)

Threat Techniques

Genian EDR in Action

Suky Castle

Kimsuky group

Spear phishing (VBS-based, Email-based 'ClickFix',
Website-based 'ClickFix' via fake recruitment site)

VBScript (obfuscated), PowerShell (obfuscated, 'ClickFix' tactic),
BabyShark series (LNK, Launcher, manifest file), AutoIt v3, QuasarRAT

Precise identification of threat flow, visibility into PowerShell execution, MITRE ATT&CK tagging, Attack Story Line, C2 communication monitoring, firewall integration, IoC updates

APT37 Attack Campaign Impersonating
 North Korean Human Rights Organization

APT37 (RedEyes, Group123)

Spear-phishing emails
(DOC, LNK)

ROKRAT (InfoStealer, Backdoor), Wiper, Steganography,
Encryption, PowerShell

Detected attempts, provides visibility for proactive response

Kimsuky Group's Triple Combo Attack
(Facebook, Email, Telegram)

Kimsuky Group
 (AppleSeed)

Facebook, Email,
Telegram-based infiltration

JSE script, VMProtect-packed DLL, tripservice.dll
(RAT, info collection, encryption)

Machine learning detection, high visibility, threat hunting, MITRE ATT&CK integration, forensics

APT37 Operation. ToyBox Story
(Disguised as Think Tank)

APT37

Spear-phishing emails
(LNK in ZIPs from Dropbox)

RoKRAT variant, Fileless execution (PowerShell, in-memory shellcode),
Screenshot, AES/RSA/XOR encryption, LoTS (Dropbox C2)

Immediate detection, attack storyline, abnormal behavior detection (XBA for cloud C2), MITRE ATT&CK

BPFDoor Linux Malware

Red Menshen (Chinese), others

Linux server targeting
(initial entry under investigation)

BPFDoor Linux backdoor, Process name randomization,
Timestamp manipulation, RC4 encryption, Reverse/Bind Shells

Visually tracks behavior, enables rapid identification and response for open-source variants

Konni APT Campaign Impersonating Korean National
Police Agency and National Human Rights Commission

Konni APT

Spear-phishing emails
(LNK, MSI, BAT in ZIPs)

LNK, AutoIt scripts (Lilith RAT), MSI packages, Scheduled
 tasks for persistence

Threat hunting, risk management, C2 communication monitoring, behavioral anomaly detection

APT Attack Leveraging Martial Law Theme
 (Kimsuky Indicators)

Kimsuky Group
(strong indicators)

Spear phishing
 (malicious URL, OS-dependent payload)

Malicious CPL file, DLL Side-loading (legitimate Google Updater),
 Quasar RAT, AES encryption, Persistence (registry)

Anomaly detection, real-time monitoring, comprehensive event collection, perfectly detected/blocked CPL files/C2 comms

APT37 Malicious HWP Cases Distributed via K Messenger

APT37

Spear phishing, K messenger group chats
 (HWP, LNK in ZIPs)

HWP (OLE exploitation), LNK, RoKRAT
 (fileless, in-memory, info exfiltration via pCloud API)

Detects abnormal HWP behavior, real-time threat notifications, XBA rules for fileless RoKRAT/C2

Kimsuky Group's Email Phishing Campaigns

Kimsuky Group (TA406)

Email phishing
 (URL phishing, often malwareless)

Primarily credential theft via phishing sites; some
 malicious DOC files with macros

Security rules (IoC registration), access history query, policy management, user notification

APT37 Cyber Reconnaissance Activities

APT37

Spear phishing (LNK),
Normal document delivery, Web beacon reconnaissance

RoKRAT
(XOR-encrypted, pCloud API, info collection, fileless via Shellcode)

Detects fileless intermediate flows, anomalous behavior, IoC patterns, event analysis

Kimsuky Group's "BlueShark" Threat Tactics

Kimsuky Group
 (BlueShark family)

Spear phishing
(impersonation, phishing sites, cloud services, LNK)

LNK, ISO, MSC, HWP (OLE data), 'VbsEdit' abuse
(DLL side-loading), Decoy documents

Anomaly detection, identifies MSC execution, detects HWP via IoC/XBA rules, selective threat response

Expanding Konni Threat Campaign
 (Linked to Kimsuky Cluster)

Konni (linked to Kimsuky)

Spear phishing
 (malicious files in emails, legitimate cloud/FTP abuse)

LNK, EXE, SCR, multi-stage script obfuscation, AES CTR encryption,
 Task Scheduler abuse, FTP for RATs, Malicious DLLs

Early detection of LNK anomalies, detailed threat info, attack storyline, AMSI event summary, custom dashboards

Konni APT Campaign Utilizing AutoIt for Defense Evasion

Konni APT (linked to Kimsuky)

Spear phishing emails
(LNK in ZIPs, sophisticated sender domain manipulation)

Malicious LNK (PowerShell, decoy HWP), AutoIt scripts
 (Lilith RAT, AsyncRAT/RftRAT with Process Hollowing), Persistence,
 Keylogger, RDP port forwarding

Detects abnormal AutoIt behavior, collects command line, identifies threat elements, displays C2 info, attack storylines, TOP 10 abnormal activities

Kimsuky APT Attack Impersonating Foreign Media Correspondent

Kimsuky APT, Mustang Panda
 (mimicking)

Spear phishing
(HWP, MSC via OneDrive, prolonged conversations)

HWP (OLE, batch file, anti-malware check, VBScript, scheduled task),
MSC (batch/VBScript, scheduled tasks, PlugX)

Effective in early detection/response for MSC, collects command line/event processes, XBA rules for abnormal behavior, forced termination, sample collection

Kimsuky APT Group's New Attack Strategy
 (Facebook Messenger, MSC files)

Kimsuky APT
 (BabyShark, ReconShark)

Fake Facebook accounts, Messenger
 conversations, malicious URL to OneDrive

Malicious.msc file (executed by mmc.exe), VBScript ('warm.vbs')
 downloads payloads, collects system info, scheduled task for persistence

High visibility into.msc command line, behavioral detection, script/HTA anomaly detection, C2 network communication detection

Multi-step DropBox commands and TutorialRAT
behind APT43

TutorialRAT and XenoRAT.

Spear-phishing with malicious LNK files
delivered via legitimate cloud services like Dropbox.

TutorialRAT (TutRAT) - C# based RAT, XenoRAT, Multi-stage payload delivery
(ps.bin, r_enc.bin, info_sc.txt, info_ps.bin, m_ps.bin, ad_ps.bin), Info Stealer, Persistence
(Mutex, Task Scheduler), Keylogger, Screenshot Capture, Browser
 Credential Stealer, Remote Control (UltraVNC).

Detects these threats through behavioral analysis, identifying suspicious PowerShell commands and Dropbox API communication.

Increase in Fileless Attacks by APT37
(RoKRAT Malware)

APT37

Spear-phishing via email
(LNK in ZIPs, cloud staging via Dropbox/pCloud)

RoKRAT variant (fileless, in-memory, info collection, exfiltration via pCloud API),
 PowerShell

Early detection (LNK, XBA rules), detects network comms, identifies fileless RoKRAT, comprehensive response, validation via simulation

Konni APT Group Targeting Bitcoin Traders

Konni APT

Spear phishing via email
(LNK in ZIP with decoy PDF)

Malicious LNK (obfuscated PowerShell, CAB extraction, VBS/BAT
chain for info collection/exfiltration/download), RC4+Base64 encryption

Early detection of abnormal behavior, immediate detection of PowerShell/batch, IoC-based diagnosis, attack storyline, C2 comms confirmation

Nation-State APT Attack Leveraging New Year's Column
 (Custom XenoRAT) 15

"fox tian"
 (linked to North Korea)

Spear-phishing email
 (LNK in password-protected ZIP via large-capacity link)

Malicious LNK (PowerShell, Base64 decode), Scheduled task for
persistence, Custom XenoRAT (RAT, HVNC)

Detects abnormal PowerShell network connections (XBA), decoy file creation, XenoRAT C2 comms

APT Attack Impersonating Webinar Invitation
 (ROKRAT)

APT37 (ROKRAT)

Spear phishing
 (malicious URL downloads LNK in ZIP from Dropbox)

Malicious LNK (long command-line, hidden spaces, replaces with decoy PDF),
fileless ROKRAT (XOR-encrypted EXE, info collection, pCloud C2)

Early detection of abnormal LNK, immediate detection of network comms, threat monitoring/analysis, proactive response

APT37 Attacks Disguised as "North Korean Market Price
Analysis Documents"

APT37

LNK, HWP, HWPX, XLSX, DOCX files
 (malicious OLE insertions)

Malicious OLE insertions (connects to C2, calls exploit)

Detects APT37 activities, limits impact, required for unknown vulnerability attacks, rapid threat identification

Kimsuky APT Group's "FlowerPower APT Campaign"

Kimsuky APT
 (FlowerPower)

Malicious OLE insertions in HWP documents
 (impersonating foreign news channels)

"FlowerPower" series tools, encrypted PowerShell commands, GitHub as C2

Secures threat visibility, early detection to minimize damage, proactively identifies threats

Kimsuky APT Group's "Storm Operation" and BabyShark
 Family Association

Kimsuky APT
 (BabyShark toolkit)

Two-track spear phishing
 (fake domains, malicious attachments/links to fake login pages)

CHM, LNK, MS Word.doc with macros, Remote template injection,
Mutex values, OPSEC failures (North Korean linguistic traces)

Utility in responding to/preventing fileless attacks, provides proactive threat intelligence

Operation DarkHorse CHM-based Attack Analysis

Kimsuky Group
(suspected)

Spear phishing emails

Malicious CHM files (execute VBS/JSE scripts embedded in HTML)

Konni APT Campaign Targeting Unification and North
 Korean Human Rights Sectors

Konni group

Spear phishing (ZIP attachments with LNK)

Malicious LNK (leak computer info, VBS/BAT call obfuscated scripts)

Provides visibility into infiltration/threat activities, effective in analyzing fileless, enables early detection of abnormal behavior

Browser In The Browser (BitB) Attack by APT37

APT37

Email phishing (mimics legitimate program, lures to
fake website with SSO)

Browser In The Browser (BitB) technique (manipulated pop-up window
within browser for credential theft)

GSC identified/analyzed, informs users/enhances products, highlights GSC's threat hunting

Tracking AsyncRAT Malware using EDR

Attackers exploiting
AsyncRAT

Phishing emails or phishing sites

AsyncRAT (open-source.NET RAT, misused for info theft/system control)

EDR used to track, GSC conducts threat case analysis to respond to evolving TTPs

Konni APT Campaign Disguised as National Tax
Service Notification

Konni APT

Spear phishing (ZIP with LNK and decoy HWP)

Malicious LNK (collects/exfiltrates info, multi-stage VBS/BAT/Powershell),
CHM, Obfuscation, "Kill switch"

GSC identified new activity, tracks/observes, detects complex abnormal terminal behaviors early, provides visibility, enables rapid response

LockBit Ransomware Attack

LockBit ransomware
organization (Russia-based)

Phishing emails with malicious IMG files
 (bypasses MOTW)

Hidden LNK, BAT, VBS, 7z.exe, Autologon.exe, LockBit ransomware; Multi-stage
execution, Privilege escalation, Persistence (autologon, safe mode boot, registry)

Detects/responds to complex, multi-stage threats, detects key events in early stages, threat event query, visual storyline

APT37 Attack Targeting macOS Users

APT37

Two-stage APT: initial phishing for password/recon
, then macOS spear phishing (ZIP with malicious.app)

Malicious AppleScript (OSA standard) for info collection, Staged
commands from C2,.app disguised as HWP

Genian EDR macOS agent detects abnormal behavior early, facilitates rapid response, blocks new threats