Actors

252 actors

Whois Team is a name that emerged in March 2013 when attackers claimed responsibility for destructive "Dark Seoul" attacks against South Korean banks and broadcasters, defacing at least one victim website and deploying disk-wiping malware; contemporaneous reporting was initially unable to determine whether a nation-state was responsible. Later analysis connected Whois Team to a second group calling itself the NewRomanic Cyber Army Team, which claimed the 2013 attacks and left messages and imagery closely resembling those later used in the November 2014 Sony Pictures intrusion, contributing to the public case for North Korean responsibility for that attack as part of an espionage campaign researchers traced back to 2009. Separate research cautioned that the Whois Team name and its listed handles could represent a false flag, noting that a South Korean white-hat capture-the-flag team also uses the "WhoIs" moniker, and that no additional attacks under the Whois Team name were subsequently observed.

Associated with: Lazarus
First seen: 2013-03 • Last seen: 2014-12

Wagemole is a campaign name Palo Alto Networks' Unit 42 introduced in November 2023, tracked internally as CL-STA-0241, for North Korea state-sponsored threat actors who seek unauthorized remote employment with organizations in the United States and elsewhere, attributing the activity with high confidence to North Korea. Unit 42 discovered Wagemole infrastructure while investigating a related campaign it named Contagious Interview, which infects software developers with malware called BeaverTail and InvisibleFerret during fake job interviews to steal data later reused to build fraudulent identities; Wagemole operators use this stolen and purchased personal data, together with forged passports and driver's licenses, AI-assisted interview study guides, and automated job-application tooling on freelance platforms, to pass background checks and secure remote technical roles, often paid through services like PayPal to obscure financial trails. Subsequent research ties Wagemole proceeds to funding North Korean weapons programs and to specific individuals, and documents the operation adapting its personas' claimed locations, malware obfuscation, and persistence techniques over time while continuing to target banking, financial-services, and information-technology organizations.

Associated with: Famous Chollima
First seen: 2023-11 • Last seen: 2026-03

WaterPlum is NTT Security Japan’s designation for a North Korea-linked actor also called Famous Chollima and PurpleBravo. The group targets financial institutions, cryptocurrency operators, and financial-technology companies worldwide and has conducted the Contagious Interview campaign since around 2023. Its operators approach targets through fraudulent employment scenarios and deploy cross-platform malware including BeaverTail, InvisibleFerret, and the actively developed OtterCookie family. OtterCookie versions observed from September 2024 through April 2025 expanded from basic file theft into Windows and macOS credential collection, browser and cryptocurrency-data theft, clipboard monitoring, shell-command execution, and sandbox detection. Later variants harvested Chrome passwords through Windows data-protection interfaces and collected MetaMask, Brave, Chrome, document, image, and macOS credential material. WaterPlum’s campaigns combine recruiter-style social engineering with rapid malware iteration to compromise developers and organizations possessing access to cryptocurrency, source code, credentials, and financially valuable systems.

Associated with: Contagious Interview
First seen: 2025-05 • Last seen: 2026-09

ZINC is Microsoft’s former designation for the North Korean threat actor also known as Lazarus Group. Microsoft publicly used the name in December 2017 while announcing coordinated disruption of the group’s malware, infrastructure, and attacker accounts. The governments of the United States, United Kingdom, Australia, Canada, New Zealand, and Japan attributed ZINC’s activity to North Korea, and Microsoft concluded that the actor was responsible for the destructive WannaCry outbreak of May 2017. Later Microsoft reporting documented ZINC targeting security researchers, technology companies, media organizations, and defense and aerospace employees through tailored social engineering. The group has posed as recruiters over professional networks and messaging services, delivered trojanized open-source applications and malicious job assessments, and deployed custom malware for reconnaissance, persistence, command execution, credential theft, and data collection. ZINC combines trusted-persona deception, software weaponization, and destructive or espionage-oriented operations against strategically valuable victims.

Associated with: Lazarus
First seen: 2017-12 • Last seen: 2022-11

puNK-003 is a threat cluster tracked by S2W's TALON research team, designated in an August 2024 report on a malicious Windows shortcut (.lnk) file, disguised as tax-evasion supporting documents, that S2W hunted on VirusTotal in April 2024. When run, the shortcut, named CURKON by S2W, executes a hidden PowerShell command that drops a decoy document, copies curl.exe into a hidden folder, and downloads an AutoIt3 interpreter with an AutoIt-scripted reimplementation of the open-source Lilith RAT, which connects to a hardcoded command-and-control server to give attackers a reverse shell, persisting via scheduled tasks configured differently depending on whether Avast antivirus is detected, with command-and-control traffic proxied through compromised WordPress sites. S2W assessed puNK-003 as related to, yet distinct from, the Konni group, citing shared LNK-argument obfuscation, overlapping AutoIt-reimplementation code including an identical function shared with Konni's AutoIt-ported Amadey malware, and matching AutoIt3 executable versions, while noting CURKON functions only as a downloader, unlike Konni's dropper-style LINKON malware.

Associated with: Konni
First seen: 2024-08 • Last seen: 2024-08

puNK-004 is S2W TALON's designation for a North Korea-linked, previously unidentified threat actor observed using the Android malware DocSwap. S2W assigned the name in March 2025 after analyzing an application disguised as a document-viewing authentication tool. The application was first identified in January 2025 and appeared designed for mobile users in South Korea. It requested extensive permissions, persisted through a foreground service and boot events, and abused accessibility services for keylogging. Through socket-based command and control, it could collect files and device information, record audio and video, manipulate the camera, and steal call logs, contacts, and messages. Infrastructure associated with the malware also hosted a phishing page impersonating a cryptocurrency service and later displayed characteristics that S2W considered a possible connection to another North Korean activity set, but the attribution remained tentative.

Associated with: Kimsuky
First seen: 2025-03 • Last seen: 2025-03

Geumseong121 is a threat group tracked and named by South Korean security firm ESTSecurity (ESRC), which first surfaced the cluster in May 2018 through a Panmunjom Declaration-themed decoy document that overlapped with Kimsuky-related indicators, then explicitly named the group the following July after an email impersonating an inter-Korean separated-families survey. Reports trace the group through named campaigns spanning 2018–2023 and note overlap with aliases used by other vendors for related North Korean activity. Its targeting consistently centers on South Korean government, unification-policy and security researchers, anti-North organizations and activists, North Korean defectors and defector-support groups, and North Korea-focused media, later expanding to political and social-issue lures and messaging-app users. TTPs include spearphishing with exploited office-document formats, fake secure-mail pages, Android spyware distributed via social media, fake charity and community apps, steganography, long-term catfishing via a popular Korean messaging app to build trust before payload delivery, disguised script-based loaders, impersonation of the Ministry of Unification and a mobile payment service, and heavy reliance on cloud storage services for command-and-control and data exfiltration.

Associated with: Scarcruft
First seen: 2018-02 • Last seen: 2023-09