ARCHIPELAGO

2023-04-05 • GoogleHow we’re protecting users from government-backed…

Google's Threat Analysis Group publicly described ARCHIPELAGO in April 2023 as its name for a subset of APT43 activity, which it had tracked since 2012. The North Korea-linked cluster targets people working on sanctions, human rights, non-proliferation, and other North Korea policy issues, including government and military personnel, think tanks, policymakers, academics, and researchers in South Korea, the United States, and elsewhere. Its operations evolved from conventional credential phishing toward rapport-building impersonation, browser-in-the-browser login pages, individualized documents hosted on cloud services, and greater malware use. ARCHIPELAGO has delivered password-protected files and layered ISO archives, encoded payloads and command instructions in cloud-hosted filenames, and used malicious browser extensions to steal credentials, cookies, and webmail contents.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster