Alluring Pisces

2024-09-09 • Paloalto NetworksThreat Assessment: North Korean Threat Groups

Palo Alto Networks Unit 42 tracks Alluring Pisces as one of at least six North Korean threat groups operating under the Reconnaissance General Bureau, also known in industry reporting as APT38, Bluenoroff, and Sapphire Sleet. The group has targeted financial institutions, cryptocurrency businesses, and automated teller machines, and has carried out significant cyber heists for financial gain. Its malware arsenal spans Windows, macOS, and Linux and includes the macOS backdoor RustBucket, delivered through a multi-stage AppleScript, Swift, and Objective-C infection chain that masquerades as a PDF viewer; KANDYKORN, a five-stage macOS payload delivered through social-engineering lures that provides information gathering, data exfiltration, and arbitrary command execution; and ObjCShellz, a lightweight Objective-C remote-shell backdoor deployed as a second-stage payload within the RustBucket campaign. The group's activity reflects a sustained focus on generating illicit revenue through cryptocurrency theft and financial-sector intrusions in support of North Korean state objectives.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster