Gleaming Pisces
2024-09-09 • Paloalto Networks • Threat Assessment: North Korean Threat Groups
Palo Alto Networks Unit 42 tracks Gleaming Pisces, also publicly known as Citrine Sleet, as a financially motivated North Korean threat actor active since at least 2018 that is closely linked to North Korea's Reconnaissance General Bureau. The group is best known for the AppleJeus operation, in which it distributed fake cryptocurrency trading applications to compromise cryptocurrency-industry organizations and individuals across Windows, macOS, and Linux systems, relying on a family of backdoors including POOLRAT and BADCALL. In a campaign identified in September 2024, Unit 42 assessed with medium confidence that Gleaming Pisces uploaded several poisoned Python packages to the public PyPI software repository, which delivered a newly identified Linux and macOS backdoor the researchers named PondRAT, assessed to be a lighter variant of POOLRAT based on shared code structure, function names, and an identical encryption key. The group's assessed objective in this supply-chain campaign was to compromise software developers' endpoints as a path to gaining access to the developers' employers or downstream customers.
-
61
Related Actors
-
691
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Gleaming Pisces reports only