NOWHERE TO HIDE CROWDSTRIKE 2023 THREAT HUNTING REPORT
2023-08-08 • Crowd Strike •
https://go.crowdstrike.com/rs/281-OBQ-266/images/report-crowdstrike-2023-threat-hunting-report.pdf
Attachments
CrowdStrike's 2023 threat hunting report highlights LABYRINTH CHOLLIMA as a DPRK adversary active across Windows, Linux, and macOS, including activity tied to the 3CX supply-chain compromise. CrowdStrike assesses the group is likely affiliated with Bureau 121 of the Reconnaissance General Bureau and describes its currency-generation operations as global in scope. The report says LABYRINTH CHOLLIMA targets financial technology and cryptocurrency organizations, updates tooling and tradecraft for Linux and macOS, and increasingly emphasizes operational security and defense evasion. CrowdStrike also notes that North Korean adversaries were the most aggressive state-sponsored actors targeting the financial sector during the reporting period.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | attacker.com | 2023-08-08 | 2023-08-08 |
| DOMAIN | fleetdeck.io | 2023-08-08 | 2023-08-08 |