CTG-6459
2021-06-15 • Secure Works • NICKEL GLADSTONE
CTG-6459 is the identifier Secureworks Counter Threat Unit researchers use for a subgroup of the broader NICKEL ACADEMY North Korean activity cluster, which CTU assesses with high confidence focuses on acquisitive financial crime against financial institutions and cryptocurrency-related organizations for the North Korean government's benefit. The group's geographic scope is unusually broad among North Korean clusters, spanning victims in North and South America, Europe, Africa, and Asia, with an apparent preference for countries with weaker financial regulatory oversight. CTU traces the cluster's prominence to the February 2016 theft of roughly eighty-one million dollars from Bangladesh Central Bank via fraudulent SWIFT messages, followed by similar operations against banks in Vietnam, Ecuador, Taiwan, Chile, and India, and probable compromise of the Polish Financial Supervision Authority website in February 2017. Since at least 2018 the group has increasingly targeted cryptocurrency exchanges and decentralized-finance platforms using trojanized trading applications to steal wallet contents, including a 2022 campaign publicly named TraderTraitor. CTU assesses the group shares tooling with NICKEL ACADEMY, with malware ties to Operation Blockbuster and the Sony Pictures intrusion.
-
34
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster