Black Alicanto
2021-09-08 • PWC • Bitcoin is silver, compromise is gold: Emerging N…
PwC publicly profiled Black Alicanto in September 2021 as an emerging North Korea-based threat actor focused on cryptocurrency theft. Its targeting broadened from cryptocurrency-wallet heists to venture-capital and investment firms around the world, using spearphishing, malicious documents, and attacker-controlled infrastructure. By 2022, PwC described the group using recruiter personas and job-themed lures, with archives containing shortcut files that invoked command execution and MSHTA to retrieve remote content. The group used double extensions and spoofed Google and other cloud services to make its delivery chain appear legitimate. PwC also observed Black Alicanto deploying successive script-based backdoors, showing an evolution from socially engineered initial access into multi-stage execution in financially motivated operations.
-
34
Related Actors
-
4
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster