Sparkling Pisces
2024-09-09 • Paloalto Networks • Threat Assessment: North Korean Threat Groups
Palo Alto Networks Unit 42 tracks Sparkling Pisces as one of at least six North Korean threat groups operating under the Reconnaissance General Bureau, known elsewhere as Kimsuky, THALLIUM, and Velvet Chollima, and describes it as conducting intelligence collection while using cybercrime to fund espionage. Nicknamed by researchers as "the king of spear phishing," the group's most notable attack targeted Korea Hydro and Nuclear Power in 2014, and it initially focused on South Korean government agencies, research institutions, and think tanks before expanding to Western countries including the United States. Sparkling Pisces maintains complex, constantly evolving infrastructure that overlaps across multiple malware strains and campaigns, and it has masqueraded as legitimate Korean companies, including signing malware with a valid stolen certificate. Its arsenal continues to grow, including an undocumented keylogger called KLogEXE and an undocumented variant of the FPSpy backdoor, both linked through shared command-and-control infrastructure to a previously reported PowerShell keylogger deployed in spear-phishing campaigns against South Korean users.
-
43
Related Actors
-
799
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Sparkling Pisces reports only