TAG-71
2023-06-06 • Recorded Future • North Korea-Aligned TAG-71 Spoofs Financial Insti…
Recorded Future's Insikt Group uses Threat Activity Group 71 (TAG-71) to designate North Korea-aligned activity that closely overlaps with public reporting on APT38, also known as Bluenoroff, Stardust Chollima, and BeagleBoyz. TAG-71 infrastructure has been used to spoof financial institutions and venture capital firms in Japan, Vietnam, Taiwan, and the United States through lookalike domains and phishing lures, including a document posing as material from a Singapore-based venture capital firm and files referencing a Department of Justice cryptocurrency-mixer report that used template injection to reach command-and-control infrastructure. Recorded Future linked prior TAG-71 infrastructure to the publicly reported CryptoCore campaign used for malware delivery, phishing, and command and control, and observed reused IP addresses previously identified in a Kaspersky report on Bluenoroff activity. This pattern is consistent with North Korean state-sponsored groups' established use of financially motivated intrusions against cryptocurrency exchanges, banks, and payment systems to generate revenue for a government facing extensive international sanctions.
-
34
Related Actors
-
232
Related Reports