Nickel Juniper

2024-10-08 • Secure WorksNICKEL JUNIPER

NickelJuniper is tracked by Secureworks Counter Threat Unit researchers, who assess with moderate confidence that the group conducts espionage on behalf of the North Korean government. The group has targeted South Korea and Russia, focusing on government entities and the cryptocurrency industry, and has displayed both financial and intelligence-gathering motivations. NickelJuniper typically gains initial access through phishing, has leveraged a known WinRAR vulnerability, and shows a preference for building intermediary infection stages with scripting languages such as VBScript and Windows Batch. Secureworks' profile also lists other industry names associated with this cluster, including Konni, Opal Sleet, and OSMIUM, and notes tooling and behavioral overlaps between NickelJuniper and two other Secureworks-tracked clusters, NICKEL FOXCROFT and NICKEL KIMBALL, suggesting related or shared North Korean cyber operations.

Related Actors

Related Reports in This Cluster

Top Authors

View Nickel Juniper reports only

View Nickel Juniper reports only