ESET APT Activity Report Q4 2022–Q1 2023
2023-05-09 • ESET •
https://www.welivesecurity.com/wp-content/uploads/2023/05/eset_apt_activity_report_q42022_q12023.pdf
Attachments
ESET’s Q4 2022–Q1 2023 APT activity report says North Korea-aligned groups ScarCruft, Andariel, and Kimsuky continued targeting South Korean and South Korea-related entities with established toolsets. The Lazarus section highlights a fake Boeing-themed job offer against employees of a defense contractor in Poland, a shift toward a data management company in India using an Accenture-themed lure, and Linux malware used in one Lazarus campaign. The broader report also notes that North Korean activity remained one part of a multi-actor APT landscape alongside China-, India-, Iran-, and Russia-aligned operations, so DPRK-specific tracking should focus on those North Korea-aligned sections rather than the full document.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | blogs.blackberry.com | 2021-02-28 | 2024-04-11 |
| HASH | df5e4a1c071b30ddca796b7cf550368… | 2023-03-21 | 2024-02-16 |
| HASH | 12ecabf01508c40cfea1ebc39582147… | 2023-05-01 | 2023-05-19 |
| HASH | 585785a2b4f6bfdcf969f2c46f933b5… | 2023-05-09 | 2023-05-09 |
| HASH | 526f48c6b3b767c119282e362eeb392… | 2023-05-09 | 2023-05-09 |
| URL | https://the.earth.li/~sgtatham/… | 2023-05-09 | 2023-05-09 |
| URL | https://telegra.ph/ | 2023-05-09 | 2023-05-09 |
| DOMAIN | the.earth.li | 2023-05-09 | 2023-05-09 |
| DOMAIN | telegra.ph | 2023-05-09 | 2023-05-09 |