APT45
2024-07-25 • Mandiant • APT45: North Korea’s Digital Military Machine
Mandiant assesses with high confidence that APT45 is a moderately sophisticated North Korean state-sponsored cyber operator active since at least 2009, and with moderate confidence that it operates in support of North Korea's Reconnaissance General Bureau. Its earliest observed activity consisted of espionage against government agencies and the defense industry from around 2017, followed by targeting of nuclear-related entities including a 2019 intrusion at a nuclear power plant in India, intellectual property theft from a multinational crop-science division in 2020, and sustained targeting of the healthcare and pharmaceutical sectors during and after the COVID-19 pandemic. APT45 has also targeted the financial sector, including a 2016 intrusion against a South Korean financial organization and 2021 spear-phishing of a South Asian bank, and Mandiant assesses with moderate confidence that it has developed and possibly deployed ransomware to generate revenue. Activity attributed to APT45 has also been publicly reported under the names Andariel, Onyx Sleet, Stonefly, and Silent Chollima, and is frequently linked to the broader Lazarus Group.
-
19
Related Actors
-
162
Related Reports