Cyber Threat Report: 'North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs'

This cybersecurity advisory from the U.S. Federal Bureau of Investigation (FBI) and its partners, highlights the cyber espionage activities of the Democratic People’s Republic of Korea (DPRK)’s Reconnaissance General Bureau (RGB) 3rd Bureau. The advisory focuses on a state-sponsored cyber group known as Andariel, which targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified technical information. The group has been observed funding its espionage activities through ransomware operations including against U.S. healthcare entities. The advisory outlines the group's methods, including exploiting known software vulnerabilities, using phishing techniques, and deploying custom malware implants and remote access tools. The advisory emphasizes the importance of critical infrastructure organizations applying timely patches for vulnerabilities, protecting web servers from web shells, monitoring endpoints for malicious activities, and strengthening authentication and remote access protections. It provides specific recommendations for mitigating risks, such as deploying endpoint agents, blocking unnecessary outbound connections, and segmenting networks to prevent lateral movement from compromised web servers. Finally, the advisory includes detailed technical information on the MITRE ATT&CK tactics, techniques, and procedures (TTPs) used by Andariel and associated indicators of compromise (IoCs).

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques