ATK117
2019-10-07 • Thales Group • https://cyberthreat.thalesgroup.com/attackers/ATK117
ATK117 is profiled by Thales and Verint in the Cyberthreat Handbook as a North Korean state-sponsored cyberthreat actor with prerogatives similar to Unit 180 of the North Korean army's General Reconnaissance Bureau, tracked under the aliases APT38 and Bluenoroff and described as a financially motivated entity within the broader Lazarus umbrella. Active since at least 2014, the group develops SWIFT-focused banking malware and cryptocurrency-theft tooling, and is linked to a series of attempted and successful bank heists, including a 2014 Southeast Asian bank intrusion, the 2015 attempted heist at TPBank, the 2016 Bangladesh Bank SWIFT theft, an October 2016 watering-hole campaign, the 2017 Far Eastern International Bank heist, and 2018 intrusions at Bancomext, three Mexican banks, and Banco de Chile, along with a 2019 campaign targeting Korean Bitcoin traders. The group has used destructive disk-wiping malware as a distraction technique, employs defense-evasion methods including false-flag artifacts and living-off-the-land tools, and maintains a broad, purpose-built malware and tooling arsenal.
-
34
Related Actors
-
232
Related Reports