#APTDown

Incident/Operation

2025-08-10 • APT Down: The North Korea Files

APTDown is a 2025 disclosure and disruption initiative built around leaked workstations, code, logs, and infrastructure associated with advanced threat operators. Material published under the name exposed exploits, attacker tooling, phishing infrastructure, and stolen data from government, telecommunications, and other networks in South Korea and Taiwan. Analysts also used the exposed infrastructure to examine Kimsuky/APT43 tracking-pixel campaigns conducted from January through May 2025. The disclosures prompted investigations into compromised public and private organizations and encompassed material from multiple threat actors rather than a single intrusion set.

Tagged Reports

« Back