ATK3
2019-10-07 • Thales Group • https://cyberthreat.thalesgroup.com/attackers/ATK3
ATK3 is the designation used by Thales, in its Cyberthreat Handbook produced with Verint, for a North Korean state-sponsored threat actor also referenced under aliases including COVELLITE, Hidden Cobra, Lazarus, and Lazarus Group. Thales ties the activity to Bureau 121 of North Korea's Reconnaissance General Bureau and notes that the "Lazarus" umbrella is often used to describe several functionally distinct North Korean cyber units, including financially focused subgroups elsewhere tracked as APT38, Stardust Chollima, or BlueNoroff. According to the Handbook, the actor's operations combine cyber espionage, destructive attacks, and financially motivated theft, targeting government, defense, financial services, energy, media, healthcare, and manufacturing organizations worldwide. Cited activity includes the 2014 Sony Pictures intrusion, the 2016 Bangladesh Bank SWIFT heist, the 2017 WannaCry outbreak, an intrusion at India's Kudankulam Nuclear Power Plant, and the Dream Job campaign that used fraudulent job offers to lure victims into installing malware.
-
60
Related Actors
-
690
Related Reports