ATK4
2019-10-07 • Thales Group • https://cyberthreat.thalesgroup.com/attackers/ATK4
Thales documented ATK4 in its 2022 Cyber Threat Handbook as a North Korean state-sponsored espionage group active since at least 2012 and linked the label to APT37. Its primary mission is collecting intelligence that supports North Korea's military, political, and economic interests. From 2014 through 2017, the group concentrated on South Korean government, defense, industry, and media targets before expanding to organizations in the Middle East, Japan, Vietnam, Russia, and the United States where North Korean interests were involved. ATK4 uses spearphishing, strategic website compromises, torrent-based delivery, Korean-language decoy documents, compromised servers, messaging platforms, cloud services, and social networks. It rapidly incorporates newly disclosed and zero-day vulnerabilities and has deployed malicious documents and multiple malware families against governments, journalists, human-rights interests, and other public- and private-sector targets.
-
26
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster