Black Artemis

2020-03-03 • PWCCyber Threats 2019: A Year in Retrospect

Black Artemis is an internal tracking name PwC introduced in a September 2020 conference presentation on the Dtrack remote-access trojan, explaining why it treats North Korea's Lazarus Group together with the related actor Andariel as a single cluster; PwC tied the two together through shared tooling, including Dtrack, traced back to 2014 and previously seen under other names, and a dropper family PwC calls TrackDrop, and described the cluster's activity as spanning breaches of financial institutions worldwide, aerospace-sector organizations, and the Kudankulam Nuclear Power Plant. Later PwC material from 2021 and 2022 continued using the label, describing Black Artemis, also referenced as temp.Hermit, as a persistent recruiter-themed social engineering operator that sends fake job offers with malicious attachments to targets in the aerospace, defense-industrial-base and manufacturing sectors as part of broader North Korean revenue-generation activity, and distinguished it from two other, separately tracked North Korean cryptocurrency-focused actors, Black Alicanto and Black Dev 2.

Related Actors

Related Reports in This Cluster

Top Authors

View Black Artemis reports only

View Black Artemis reports only