NOWHERE TO HIDE CROWDSTRIKE 2023 THREAT HUNTING REPORT

2023-08-08 Crowd Strike

https://go.crowdstrike.com/rs/281-OBQ-266/images/report-crowdstrike-2023-threat-hunting-report.pdf

Attachments

report-crowdstrike-2023-threat-hunting-report.pdf (1 MB)

Thumbnail for NOWHERE TO HIDE CROWDSTRIKE 2023 THREAT HUNTING REPORT

CrowdStrike's 2023 threat hunting report highlights LABYRINTH CHOLLIMA as a DPRK adversary active across Windows, Linux, and macOS, including activity tied to the 3CX supply-chain compromise. CrowdStrike assesses the group is likely affiliated with Bureau 121 of the Reconnaissance General Bureau and describes its currency-generation operations as global in scope. The report says LABYRINTH CHOLLIMA targets financial technology and cryptocurrency organizations, updates tooling and tradecraft for Linux and macOS, and increasingly emphasizes operational security and defense evasion. CrowdStrike also notes that North Korean adversaries were the most aggressive state-sponsored actors targeting the financial sector during the reporting period.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN attacker.com 2023-08-08 2023-08-08
DOMAIN fleetdeck.io 2023-08-08 2023-08-08

Related Actors

Related Reports

« Back