UNC785

2023-03-28 • MandiantAPT43: North Korean Group Uses Cybercrime to Fund…

The Mandiant report tagged to this cluster describes it throughout under the public name APT43, a prolific North Korean cyber operator that Mandiant has tracked since 2018 and assesses with high confidence supports the Reconnaissance General Bureau's collection priorities. The group combines moderately sophisticated technical capabilities with aggressive spear-phishing and social-engineering campaigns against South Korean and U.S. government organizations, academics, and think tanks focused on Korean-peninsula geopolitical and nuclear-security issues, and has also targeted Japan and Europe; from October 2020 through October 2021 it notably shifted focus toward health and pharmaceutical-sector targets, likely in support of North Korea's pandemic-response priorities. The actor builds numerous fraudulent personas, including posing as journalists or think-tank analysts, to build rapport with targets and obtain strategic analysis directly, and also uses spoofed domains and stolen contact lists for credential harvesting. Beyond espionage, the group is assessed to fund itself through cybercrime, including stealing and laundering cryptocurrency, and has collaborated with other North Korean cyber operators, underscoring its role within the broader North Korean cyber apparatus.

Related Actors

Related Reports in This Cluster

Top Authors

View UNC785 reports only

View UNC785 reports only