ITG03

2021-11-02 • IBMITG03 Analysis Report

ITG03 is IBM X-Force IRIS's cover term for a North Korean state-sponsored threat group active since at least 2009. IBM describes significant overlap with the publicly reported Lazarus Group and two principal objectives: espionage and asymmetric operations supporting state priorities, and financially motivated crime. Earlier activity targeted government, military, academic, nonprofit, and defector-related interests for political and security intelligence, while activity since at least 2016 increasingly targeted banks, SWIFT environments, cryptocurrency exchanges, and individual cryptocurrency users. ITG03 commonly performs targeted reconnaissance and spearphishing, including fake job opportunities, and uses watering holes, compromised domains, global proxy infrastructure, custom malware, and destructive payloads. Its operators collect credentials and sensitive data, capture screens and keystrokes, move funds, and may deploy ransomware or wipers to disrupt operations, conceal theft, or demonstrate force.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster