TEMP.Hermit

2023-03-20 • Fireeyehttps://www.fireeye.com/blog/kr-threat-research/2017/09/temp-hermit-leveraged-tax-themed-lures-to-distribute-peachpit-malware.html

TEMP.Hermit is Mandiant’s designation for a North Korean actor active since at least 2013 and commonly associated with activity broadly called Lazarus Group. Mandiant assesses that its operations represent Pyongyang’s effort to collect strategic intelligence supporting North Korean interests. The actor targets government, defense, telecommunications, and financial institutions worldwide, with espionage rather than cryptocurrency theft as its primary mission. Its activity overlaps with AppleJeus tooling, and Mandiant has observed broader sharing of tools, personnel, and targeting across North Korea’s cyber apparatus. During the COVID-19 pandemic, TEMP.Hermit-related resources also overlapped with APT43 activity in a temporary task-force-like cluster targeting healthcare and research organizations for treatment and vaccine information. This flexible operating environment complicates strict attribution, but TEMP.Hermit remains distinguished by long-running strategic collection against government, military, communications, and other high-value institutional targets.

Related Actors

Related Reports in This Cluster

Top Authors

View TEMP.Hermit reports only

View TEMP.Hermit reports only