#NoPineapple

Incident/Operation

2023-02-02 • No Pineapple! - DPRK Targeting of Medical Research and Technology Sector

No Pineapple was a cyber-espionage intrusion observed through the fourth quarter of 2022 and attributed with strong confidence to the North Korean state-sponsored Lazarus Group. It targeted public- and private-sector research organizations, medical research, energy, technology supply chains, and potentially technology with military applications, with intelligence collection assessed as the primary motive. Attackers exploited known vulnerabilities in unpatched Zimbra systems, deployed web shells and custom binaries, abused legitimate Windows and Unix utilities, and used proxying and tunneling tools with layered command infrastructure. Approximately 100 GB of data was exfiltrated, with no destructive action observed before disruption.

Tagged Reports

« Back