Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.005 Visual Basic |
MalwareBabyShark | BabyShark can execute additional VisualBasic content. |
| T1566 Phishing |
GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| T1583 Acquire Infrastructure |
GroupKimsuky | Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1584.001 Domains |
GroupKimsuky | Kimsuky has compromised legitimate sites and used them to distribute malware. |
| T1585 Establish Accounts |
GroupKimsuky | Kimsuky has leveraged stolen PII to create accounts. |
| T1585.002 Email Accounts |
GroupKimsuky | Kimsuky has created email accounts for phishing operations. |
| T1587.001 Malware |
GroupKimsuky | Kimsuky has developed its own unique malware such as MailFetch.py for use in operations. |
| T1588.002 Tool |
GroupKimsuky | Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec. |
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1598 Phishing for Information |
GroupKimsuky | Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets. |
| T1608.001 Upload Malware |
GroupKimsuky | Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox. |
| T1620 Reflective Code Loading |
GroupKimsuky | Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`. |
| T1657 Financial Theft |
GroupKimsuky | Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.