ATT&CKReferencesMandiant APT43 March 2024

Mandiant APT43 March 2024

Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.005
Visual Basic
MalwareBabyShark

BabyShark can execute additional VisualBasic content.

T1566
Phishing
GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

T1583
Acquire Infrastructure
GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1584.001
Domains
GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

T1585
Establish Accounts
GroupKimsuky

Kimsuky has leveraged stolen PII to create accounts.

T1585.002
Email Accounts
GroupKimsuky

Kimsuky has created email accounts for phishing operations.

T1587.001
Malware
GroupKimsuky

Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.

T1588.002
Tool
GroupKimsuky

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.

T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1598
Phishing for Information
GroupKimsuky

Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets.

T1608.001
Upload Malware
GroupKimsuky

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox.

T1620
Reflective Code Loading
GroupKimsuky

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.

T1657
Financial Theft
GroupKimsuky

Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.