APT43

2023-03-28 • MandiantAPT43: North Korean Group Uses Cybercrime to Fund…

APT43 is a North Korean state-sponsored cyber operator publicly identified by Mandiant in March 2023, assessed to have been active since at least 2018 in support of the Reconnaissance General Bureau (RGB), North Korea's main foreign intelligence service. Mandiant and other researchers noted that activity later consolidated under the APT43 name had previously been publicly reported under other identifiers, including Kimsuky and Thallium. The group's primary mission is strategic intelligence collection aligned with Pyongyang's geopolitical and nuclear priorities, achieved mainly through tailored spear-phishing, credential harvesting via spoofed websites, and elaborate fraudulent personas (including posing as journalists and think-tank analysts) to build rapport with targets. Its focus is regionally centered on South Korea and the United States, with additional targeting of Japan and Europe, spanning government, defense, academic, non-profit, media, and manufacturing sectors tied to foreign policy and nuclear/nonproliferation issues. To fund its espionage operations, APT43 steals and launders cryptocurrency through hash-rental and cloud-mining services, and it has coordinated with other North Korean cyber operators on shared campaigns and tasking.

Related Actors

Related Reports in This Cluster

Top Authors

View APT43 reports only

View APT43 reports only