Group 123 was named by Cisco Talos, which in January 2018 assessed with high confidence that the actor was responsible for six campaigns spanning 2017 into early 2018 against South Korean targets, including operations nicknamed Golden Time, Evil New Year, North Korean Human Rights, FreeMilk, and a disk-wiping campaign called Are You Happy. The group relies on spear-phishing emails, written in fluent Korean, that deliver malicious Hangul Word Processor documents exploiting a known Hangul vulnerability or, against non-Korean financial-sector targets, Microsoft Office documents exploiting a separate known flaw, to install the ROKRAT remote access tool, sometimes staged through additional loader malware. Group 123 has compromised legitimate infrastructure, including a Korean university's mail system and a government legal-services website, to distribute and host lures, and used a ROKRAT-based disk-wiper module. Later reporting, including from Cyfirma, describes the group as active since at least 2012 and tracked under other industry names including APT37, Reaper, and ScarCruft, noting continued espionage against defense, aerospace, and nuclear-related targets alongside ransomware use for funding.
Actors
249 actors
Group77 is an alias associated with the Lazarus Group, the North Korean state-sponsored threat actor. Cisco Talos referenced the name in 2016 while summarizing Novetta's Operation Blockbuster research, which linked a cluster of related malware families to a single group of threat actors behind multiple high-profile attacks carried out over roughly nine years. In 2019 the U.S. Treasury's Office of Foreign Assets Control formally listed GROUP 77 as one of numerous aliases for the sanctioned entity Lazarus Group, alongside names such as Hidden Cobra, Guardians of Peace, and Zinc, identifying the group as based in Pyongyang's Potonggang District and subject to North Korea sanctions regulations. Group77 is therefore best understood not as a distinct organization but as one of several public labels applied to the broader Lazarus Group activity attributed to North Korea's state cyber apparatus.
In late November 2014, attackers using the name Guardians of Peace, sometimes shortened to GOP, breached the network of Sony Pictures Entertainment, disabling systems for days and releasing large volumes of internal data. The leaked material, totaling tens of gigabytes released across multiple batches, exposed personal information for roughly four thousand current and former employees, including tens of thousands of Social Security numbers, plaintext passwords, financial and human-resources records, and internal credentials, alongside several unreleased films that were downloaded widely once posted. A person identifying as the group's leader corresponded briefly with researchers, promising further leaks and inviting others to join the group's cause. Speculation quickly linked the intrusion to North Korea, coinciding with Sony's planned December 2014 release of a comedy depicting the assassination of North Korea's leader, a film North Korea had objected to at the United Nations without naming it; the FBI opened an investigation into possible North Korean involvement, though some journalists at the time disputed that attribution, citing reporting that the intrusion involved wiper malware capable of rendering infected systems unusable.
HASTATI is not presented as an actor name in the associated technical analysis. It is the fixed string repeated by a Dark Seoul-era wiper variant while overwriting the master boot record, volume boot record, and logical drives. That wiper was configured to begin destructive execution on or after March 20, 2013 at 14:00 local time.
Tencent's threat intelligence center named this actor Hermit in December 2018 after identifying a new intrusion set whose loading mechanism and download infrastructure closely resembled a previously exposed FTP-based remote-access trojan the company had already linked to the Konni cluster and suspected of ties to Darkhotel activity. The name refers to the group's decoy documents, whose malicious lure content stayed hidden until a victim enabled macros. Tencent traced the activity to at least April 2018 and found it continuing into 2020, with primary targets being political figures, government departments, non-governmental organizations, trade companies, and media connected to the Korean peninsula. Its consistent method is spear-phishing email carrying Office documents with malicious macros; once enabled, the macro fetches and decodes a downloader that retrieves an architecture-specific package installing a backdoor capable of file transfer, process management, and remote command execution, at times paired with a hidden-interface remote-control tool. By 2020 the group had refined its user-account-control bypass techniques and continued using topical lures, including pandemic and Korean-policy themes, while exfiltrating encrypted victim data over file-transfer-protocol infrastructure.
Expel first identified and named this group in April 2026, introducing it as Expel-TA-0001, also known as HexagonalRodent, an activity cluster it assesses with high confidence to be North Korean, DPRK, state-sponsored, likely a subgroup or spin-off of a larger organization, and with medium-high confidence a subset of the cluster CrowdStrike tracks as Famous Chollima. The group is financially motivated, targeting Web3 and cryptocurrency developers through fake recruiter outreach and job offers on LinkedIn and fake company websites, delivering backdoored coding skills assessments that execute the BeaverTail, OtterCookie, and InvisibleFerret malware to steal browser, keychain, and cryptocurrency wallet credentials. It has also conducted at least one software supply-chain compromise. The group makes heavy use of generative AI tools to build malware, fake personas, and websites, and internal panel data indicated a structure of roughly thirty-one operators across six teams. Over a three-month period it exfiltrated an estimated twelve million dollars in cryptocurrency from more than 2,700 compromised systems.
HIDDEN COBRA is the designation the United States government uses for malicious cyber activity conducted by the North Korean government, which commercial security reporting has also linked to the Lazarus Group. According to a 2017 joint technical alert from the Department of Homeland Security and FBI, the actor has operated since at least 2009, targeting media, aerospace, financial, and critical-infrastructure organizations in the United States and globally, and using tools including DDoS botnets, keyloggers, remote access trojans, and destructive wiper malware. A separate joint alert from DHS, the FBI, and the Treasury Department detailed a financially motivated operation the government named FASTCash, active since at least late 2016, in which the actors compromised bank payment-switch application servers, often running outdated and unsupported software, and used their understanding of international financial messaging standards to inject fraudulent but legitimate-looking approval messages. This enabled simultaneous fraudulent cash withdrawals from ATMs in dozens of countries in single incidents during 2017 and 2018, netting the actors tens of millions of dollars from targeted banks in Africa and Asia.
ITG03 is IBM X-Force IRIS's cover term for a North Korean state-sponsored threat group active since at least 2009. IBM describes significant overlap with the publicly reported Lazarus Group and two principal objectives: espionage and asymmetric operations supporting state priorities, and financially motivated crime. Earlier activity targeted government, military, academic, nonprofit, and defector-related interests for political and security intelligence, while activity since at least 2016 increasingly targeted banks, SWIFT environments, cryptocurrency exchanges, and individual cryptocurrency users. ITG03 commonly performs targeted reconnaissance and spearphishing, including fake job opportunities, and uses watering holes, compromised domains, global proxy infrastructure, custom malware, and destructive payloads. Its operators collect credentials and sensitive data, capture screens and keystrokes, move funds, and may deploy ransomware or wipers to disrupt operations, conceal theft, or demonstrate force.
ITG10 is IBM Security X-Force’s designation for a threat group whose activity overlaps with APT37 and ScarCruft. X-Force publicly described the cluster in June 2023 after uncovering an April 2023 phishing campaign that delivered RokRAT through malicious Windows shortcut files and obfuscated PowerShell. The observed lures impersonated credible senders and referenced South Korean parliamentary committees, broadcasters, think tanks, energy projects, manufacturing, and supply chains. X-Force assessed that probable targets included South Korean government personnel, universities, researchers, journalists, dissidents, and organizations holding strategic, political, or military information concerning the Korean Peninsula. The campaign used ZIP or ISO containers, decoy documents, LNK files, scripts, and cloud-hosted payloads. RokRAT provided command execution, file transfer, data exfiltration, and keylogging capabilities, supporting an intelligence-collection objective aligned with North Korean interests.
IBM X-Force profiles ITG16 as a North Korean government state-sponsored threat group active since at least 2012 that has traditionally targeted South Korean organizations, including diplomatic and national-security personnel, human rights groups, media, utilities, and think tanks. Its operations and targeting align with North Korean government objectives: fulfilling intelligence requirements, conducting disruptive operations against adversaries, and targeting financial institutions for illicit fundraising. Over time the group has broadened its target set to countries including South Korea, the United States, Japan, Russia, China, Germany, the United Kingdom, South Africa, and India, generally organizations tied to diplomatic or commercial activity involving the Korean peninsula or regional security. During the 2010s it expanded its victim pool to financial institutions and cryptocurrency, and in 2021 it targeted organizations and pharmaceutical companies associated with COVID-19 vaccine development.
Volexity introduced the name InkySquid in an August 2021 report describing a North Korean threat actor whose activity broadly corresponds to what other researchers publicly track as ScarCruft or APT37. Volexity documented a strategic web compromise of a South Korean online newspaper covering North Korea-related news, in which malicious code injected into the site's scripts redirected Internet Explorer and Edge users to attacker infrastructure exploiting browser vulnerabilities, delivering a Cobalt Strike stager followed by a backdoor using cloud services such as Microsoft's Graph API for command and control. A follow-up investigation found the same backdoor deployed alongside RokRAT, a remote-access trojan previously attributed to ScarCruft, on a system belonging to an individual frequently targeted by North Korean actors, with the malware performing keylogging, clipboard theft, file collection, and encrypted exfiltration. A later analysis described the group as active for roughly a decade, relying on social engineering and n-day exploits against browsers and Korean word-processing software; researchers also attributed a macOS backdoor sharing RokRAT's cloud-based infrastructure and code structure to the same group, used to exfiltrate documents, screenshots, and keystrokes.
IsOne is the self-given alias used by the actor behind a June 2012 intrusion into South Korean newspaper JoongAng Ilbo, in which the attacker defaced the outlet's website and attempted to wipe its news-production servers, leaving a message threatening further attacks. South Korea's National Police Agency adopted the name after finding it used as a compromised PC hostname in the attacker's infrastructure and determined the intruder had accessed the target for reconnaissance since at least April 2012, routed the attack through relay servers across roughly ten countries, and connected from IP ranges assigned to North Korea, including addresses tied to North Korea's Ministry of Posts and Telecommunications. Investigators found one relay server had also been used in a March 2011 DDoS attack and a 2011 Nonghyup bank hacking incident, and identified malware overlapping in algorithm and key values with earlier 2009 and 2011 DDoS and email-malware incidents. A later ESTsecurity analysis linked IsOne's document macro code, command-string formatting, and file-wiping technique to a subsequently discovered malicious document attributed to an author called sinbad, suggesting continued activity years afterward.