EXECUTIVE SUMMARY
It highlights ongoing cyber espionage activities associated with the DPRK and RGB’s 3rd Bureau, specifically targeting defense, aerospace, nuclear, and engineering entities. This group, known as Andariel also referred to as Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, aims to obtain sensitive information to advance DPRK’s military and nuclear programs. Entities in various countries, including Japan and India, remain at risk from this threat. Andariel funds its espionage through ransomware attacks on U.S. healthcare entities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
It highlights ongoing cyber espionage activities associated with the DPRK and RGB’s 3rd Bureau, specifically targeting defense, aerospace, nuclear, and engineering entities. This group, known as Andariel also referred to as Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, aims to obtain sensitive information to advance DPRK’s military and nuclear programs. Entities in various countries, including Japan and India, remain at risk from this threat. Andariel funds its espionage through ransomware attacks on U.S. healthcare entities.[emaillocker id="1283"]
The RGB 3rd Bureau actors finance their espionage through ransomware operations against U.S. healthcare entities. They exploit known vulnerabilities, such as Log4j, to gain initial access via web servers, deploying web shells and gaining access to sensitive information. They use standard system discovery and enumeration techniques, persistence mechanisms like Scheduled Tasks, and credential-stealing tools such as Mimikatz for privilege escalation. The actors deploy custom malware implants, remote access tools (RATs), and open-source tools for execution, lateral movement, and data exfiltration. Additionally, they conduct phishing campaigns using malicious attachments, including Microsoft Windows Shortcut File (LNK) and HTML Application (HTA) script files. The group employs a variety of reconnaissance techniques and leverages CVEs like CVE-2023-46604, CVE-2023-3519, and CVE-2023-27997. They utilize both custom and commodity malware, including RATs like MagicRAT, Valefor, and NukeSped, for remote access, data manipulation, and command and control (C2) operations.
To counter these threats, organizations, especially in critical infrastructure, should apply timely patches for vulnerabilities, protect web servers from web shells, monitor endpoints for malicious activity, and strengthen authentication and remote access protections. By implementing these mitigations, organizations can enhance their cybersecurity posture against ongoing cyber espionage activities by the DPRK's RGB 3rd Bureau.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1591 | Gather Victim Org Information |
| T1592 | Gather Victim Host Information | |
| T1595 | Active Scanning | |
| T1596 | Search Open Technical Databases | |
| Resource Development | T1587 | Develop Capabilities |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1083 | File and Directory Discovery |
| T1087 | Account Discovery | |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1560 | Archive Collected Data |
| T1039 | Data from Network Shared Drive | |
| Command and Control | T1572 | Protocol Tunneling |
| T1071 | Application Layer Protocol | |
| T1090 | Proxy | |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
| T1567 | Exfiltration Over Web Service |
REFERENCES:
The following reports contain further technical details:
https://www.cisa.gov/sites/default/files/2024-07/aa24-207a-dprk-cyber-group-conducts-global-espionage-campaign.pdf