EXECUTIVE SUMMARY
APT45 is a long-running, moderately North Korean cyber operator that has carried out espionage campaigns. The group has expanded into financially motivated operations, including the suspected development and deployment of ransomware, setting it apart from other North Korean operators. APT45 is strongly associated with a distinct genealogy of malware families and has frequently targeted critical infrastructure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
APT45 is a long-running, moderately North Korean cyber operator that has carried out espionage campaigns. The group has expanded into financially motivated operations, including the suspected development and deployment of ransomware, setting it apart from other North Korean operators. APT45 is strongly associated with a distinct genealogy of malware families and has frequently targeted critical infrastructure.[emaillocker id="1283"]
APT45's operations are characterized by its use of a blend of publicly available tools and custom malware. The group employs tools such as 3PROXY and ROGUEEYE, alongside unique malware families with shared characteristics like re-used code and custom encoding. Notable activities include targeting South Korean financial institutions, nuclear research facilities, and crop science sectors. There are indications that APT45 has engaged in ransomware activities, potentially using variants like MAUI and SHATTEREDGLASS, though this remains unconfirmed. The group’s malware overlaps with other North Korean clusters, including Andariel, Onyx Sleet, Stonefly, and Silent Chollima, and is frequently linked to Lazarus Group.
APT45 remains one of North Korea’s most enduring and versatile cyber operators. The group’s shift from traditional espionage to include financially motivated cybercrime and ransomware represents a broader strategy by North Korea to align its cyber capabilities with national priorities. As APT45 continues to target diverse sectors and utilize malware, its activities will likely remain a significant concern for global. The group’s operations underscore the increasing reliance of North Korea on cyber activities as a tool for advancing its strategic goals.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1203 | Exploitation for Client Execution |
| Persistence | T1136 | Create Account |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Defense Evasion | T1070 | Indicator Removal |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1083 | File and Directory Discovery |
| Collection | T1119 | Automated Collection |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1499 | Endpoint Denial of Service |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/07/north-korean-hackers-shift-from-cyber.html