TA444

2023-01-25 • ProofpointTA444: The APT Startup Aimed at Acquisition (of Y…

TA444 is Proofpoint’s designation for a North Korean state-sponsored group whose activity overlaps with APT38, BlueNoroff, BlackAlicanto, Stardust Chollima, and COPERNICIUM. Active in its cryptocurrency-focused form since at least 2017, the actor is primarily tasked with generating revenue for the North Korean government. It historically targeted banks and later concentrated on cryptocurrency companies, exchanges, bridges, and individuals. TA444 uses tailored job, investment, salary, and blockchain-themed lures delivered through email, LinkedIn, marketing platforms, cloud storage, and malicious files including LNK, ISO, VHD, MSI, CHM, and remote-template documents. Its malware ecosystem includes CageyChameleon, Astraeus, Cardinal, msoRAT, Rantankba, and other backdoors for profiling, persistence, credential collection, and theft. Proofpoint describes a highly adaptive operator that rapidly tests new delivery methods, reuses dedicated infrastructure, and combines social engineering, malware deployment, credential harvesting, and laundering mechanisms to obtain substantial financial returns.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster