Threat Advisory

North Korean APT45 Target Critical Infrastructure and Healthcare with Ransomware Attacks

Threat: Malware
Threat Actor Name: APT45
Threat Actor Type: State-Sponsored
Targeted Region: South Korea
Threat Actor Region: North Korea
Targeted Sector: Government & Defense, Finance & Banking, Healthcare, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

APT45 is a long-running, moderately North Korean cyber operator that has carried out espionage campaigns. The group has expanded into financially motivated operations, including the suspected development and deployment of ransomware, setting it apart from other North Korean operators. APT45 is strongly associated with a distinct genealogy of malware families and has frequently targeted critical infrastructure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

APT45 is a long-running, moderately North Korean cyber operator that has carried out espionage campaigns. The group has expanded into financially motivated operations, including the suspected development and deployment of ransomware, setting it apart from other North Korean operators. APT45 is strongly associated with a distinct genealogy of malware families and has frequently targeted critical infrastructure.[emaillocker id="1283"]

 

APT45's operations are characterized by its use of a blend of publicly available tools and custom malware. The group employs tools such as 3PROXY and ROGUEEYE, alongside unique malware families with shared characteristics like re-used code and custom encoding. Notable activities include targeting South Korean financial institutions, nuclear research facilities, and crop science sectors. There are indications that APT45 has engaged in ransomware activities, potentially using variants like MAUI and SHATTEREDGLASS, though this remains unconfirmed. The group’s malware overlaps with other North Korean clusters, including Andariel, Onyx Sleet, Stonefly, and Silent Chollima, and is frequently linked to Lazarus Group.

 

APT45 remains one of North Korea’s most enduring and versatile cyber operators. The group’s shift from traditional espionage to include financially motivated cybercrime and ransomware represents a broader strategy by North Korea to align its cyber capabilities with national priorities. As APT45 continues to target diverse sectors and utilize malware, its activities will likely remain a significant concern for global. The group’s operations underscore the increasing reliance of North Korea on cyber activities as a tool for advancing its strategic goals.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1203 Exploitation for Client Execution
 Persistence T1136 Create Account
Privilege Escalation T1068 Exploitation for Privilege Escalation
Defense Evasion T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
Discovery T1083 File and Directory Discovery
Collection T1119 Automated Collection
 Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1499 Endpoint Denial of Service

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/07/north-korean-hackers-shift-from-cyber.html

[/emaillocker]
crossmenu