Slow Pisces

2024-06-28 • Paloalto NetworksThreat Actor Groups Tracked by Palo Alto Networks…

Palo Alto Networks' Unit 42 tracks Slow Pisces as a North Korean state-sponsored threat group operating under the Reconnaissance General Bureau and believed to be a spin-off of the Lazarus Group. Active since around 2020, the group is primarily financially motivated, targeting large cryptocurrency-sector organizations to generate revenue for the regime, reportedly stealing over a billion US dollars from the sector in 2023 alone through fake trading applications, malicious packages, and software supply-chain compromises; later reporting also tied the group to large thefts from a Japan-based cryptocurrency company and a Middle East-based exchange. A dedicated 2025 Unit 42 report describes a campaign in which operators posed as recruiters on LinkedIn, sent benign job-description PDFs, then directed applicants to 'coding challenge' code repositories adapted from legitimate open-source projects. These repositories quietly fetched data from an attacker-controlled endpoint alongside legitimate sources, and validated targets received a payload via unsafe deserialization that installed custom malware for loading and stealing data, harvesting system, application, keychain, and cloud-credential information. The group has secondarily compromised aerospace, defense, and industrial organizations for espionage purposes.

Related Actors

Related Reports in This Cluster

Top Authors

View Slow Pisces reports only

View Slow Pisces reports only