Slow Pisces
2024-06-28 • Paloalto Networks • Threat Actor Groups Tracked by Palo Alto Networks…
Palo Alto Networks' Unit 42 tracks Slow Pisces as a North Korean state-sponsored threat group operating under the Reconnaissance General Bureau and believed to be a spin-off of the Lazarus Group. Active since around 2020, the group is primarily financially motivated, targeting large cryptocurrency-sector organizations to generate revenue for the regime, reportedly stealing over a billion US dollars from the sector in 2023 alone through fake trading applications, malicious packages, and software supply-chain compromises; later reporting also tied the group to large thefts from a Japan-based cryptocurrency company and a Middle East-based exchange. A dedicated 2025 Unit 42 report describes a campaign in which operators posed as recruiters on LinkedIn, sent benign job-description PDFs, then directed applicants to 'coding challenge' code repositories adapted from legitimate open-source projects. These repositories quietly fetched data from an attacker-controlled endpoint alongside legitimate sources, and validated targets received a payload via unsafe deserialization that installed custom malware for loading and stealing data, harvesting system, application, keychain, and cloud-credential information. The group has secondarily compromised aerospace, defense, and industrial organizations for espionage purposes.
-
34
Related Actors
-
3
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster