Cyber Threat Report: 'Operation Blockbuster: Unraveling the Long Thread of the Sony Attack'

Report Author Novetta
Publication Date 2016-02-24
Original Reporting Source
Attributed to Nation North Korea
Related Intrusion Sets Lazarus Group
Victim Sectors Financial Services, Aerospace, Defense

This report by Novetta covers 'Operation Blockbuster' which was a Novetta-led coalition of private industry partners aiming to understand and disrupt the Lazarus Group intrusion set. The report provides an analysis of the malware used in the cyber attack against Sony Pictures Entertainment in 2014 and traces the groups activities by to at least 2009. The report finds that the malware seen in Operation Blockbuster and attributed to the Lazarus Group has been used to target government, media, military, aerospace, financial, and critical infrastructure entities. Geographically they link targeting to South Korea and the United States.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph