Skip to main content
Mallory
🇰🇵 KP13 malware families

DPRK cyber actors

Also known asdprk_cyber_actors

DPRK cyber actors are described in a joint #StopRansomware advisory as Democratic People’s Republic of Korea state-sponsored ransomware operators. The content states they have conducted ongoing ransomware activity targeting Healthcare and Public Health sector organizations, including U.S. and South Korean healthcare entities, as well as other critical infrastructure. The advisory also notes DPRK cyber operations targeting the United States and South Korea governments, including Department of Defense Information Networks and Defense Industrial Base member networks. According to the content, these actors use ransomware operations to generate revenue, with some proceeds assessed to support DPRK national-level priorities and objectives. Reported ransomware associated with these actors includes Maui and H0lyGh0st. The content also states they have been observed using or possessing publicly available encryption tools including BitLocker, Deadbolt, ech0raix, GonnaCry, Hidden Tear, Jigsaw, LockBit 2.0, My Little Ransomware, NxRansomware, Ryuk, and YourRansom, and that they have at times portrayed themselves as other ransomware groups, including REvil. The described tradecraft includes acquiring infrastructure by generating domains, personas, and accounts; procuring infrastructure, IP addresses, and domains using cryptocurrency generated through illicit cybercrime such as ransomware and cryptocurrency theft; and obfuscating attribution through third-country identities, foreign intermediaries, VPNs, VPSs, and third-country IP addresses. For initial access, the content states they exploit known vulnerabilities including CVE-2021-44228 (Log4Shell), CVE-2021-20038 (SonicWall SMA100), and CVE-2022-24990 (TerraMaster TOS). They are also described as distributing Trojanized files for the X-Popup messenger used by small and medium hospitals in South Korea, including via the domains xpopup.pe[.]kr and xpopup[.]com. Post-compromise, the actors are described as using staged payloads and customized malware to conduct reconnaissance, transfer files, execute shell commands, collect victim information, and send that information to actor-controlled remote hosts. They then deploy ransomware, set ransom demands in bitcoin, and communicate with victims via Proton Mail accounts. Known aliases and subgroup names directly mentioned in the content: Maui and H0lyGh0st.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇰🇷 South Korea

Where they're from

Attributed origin per open-source reporting.

  • KP
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
TA0001
Initial Access
3 techniques
T1133
External Remote Services
T1190
Exploit Public-Facing Application
T1195
Supply Chain Compromise
TA0003
Persistence
1 technique
T1133
External Remote Services
TA0007
Discovery
1 technique
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
ACTIVITY FEED

Recent activity

1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal13

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.