Summary:
Insikt Group has uncovered malicious cyber threat activity targeting financial institutions and venture capital firms in Japan, Vietnam, and the United States. The group behind these activities, referred to as Threat Activity Group 71 (TAG71), shows significant overlap with publicly reported North Korean state-sponsored APT38 (also known as Bluenoroff, Stardust Chollima, and BeagleBoyz) activity.[/subscribe_to_unlock_form]
Summary:
Insikt Group has uncovered malicious cyber threat activity targeting financial institutions and venture capital firms in Japan, Vietnam, and the United States. The group behind these activities, referred to as Threat Activity Group 71 (TAG71), shows significant overlap with publicly reported North Korean state-sponsored APT38 (also known as Bluenoroff, Stardust Chollima, and BeagleBoyz) activity.[emaillocker id="1283"]
North Korean-linked APT groups have a history of financially motivated intrusion campaigns targeting cryptocurrency exchanges, commercial banks, and e-commerce payment systems worldwide. The recent TAG71 campaign aligns with this pattern, likely supporting the North Korean government's ongoing efforts to generate funds amidst international sanctions. The targeting of investment banking and venture capital firms poses a risk of exposing sensitive information, potentially leading to legal or regulatory consequences, compromised business negotiations, or damage to a company's strategic investment portfolio. Insikt Group adhered to responsible disclosure procedures before publishing the findings.
Insikt Group discovered three files associated with the reported infrastructure, including a ZIP file delivered containing a password-protected PDF titled "Arbor Ventures." The accompanying text file provides the password, and upon entering it, a document supposedly associated with Arbor Ventures, a Singapore-based VC firm, opens. However, the authenticity of the document remains uncertain. No indications of maliciousness or network communication to a potential command-and-control server were observed in this instance. Another ZIP file titled "Shotdown of Chipmixer (DOJ Report).docx" and "Suspected Addresses.docx" was downloaded from the domain. These files employ template injection to establish communication with a command-and-control server. Unfortunately, the server was inactive during analysis, preventing further examination. The final file, "Daiwa Securities Group.docx," associated with this cluster was downloaded from the domain. It contains a template injection configuration but points to a local file instead of a command-and-control server, suggesting it may be a test file or template.
TAG71 and other North Korean state-sponsored threat actors have a track record of successful attacks on global financial institutions to extract funds for the regime. This report's findings align with their modus operandi, exploiting the brand names and reputations of Asian and U.S. financial organizations in spear-phishing attacks against employees and customers. The compromise of financial and investment firms and their clients can lead to the exposure of sensitive information, legal repercussions, disrupted business negotiations, or damage to strategic investment portfolios.
Threat Profile:

References:
The following reports contain further technical details:
https://go.recordedfuture.com/hubfs/reports/cta-2023-0606.pdf
[/emaillocker]