north_korean_apts
North Korean APT activity referenced in the content includes exploitation of the React2Shell vulnerability (CVE-2025-55182) in Next.js/React Server Components and the use of common “living off the land” tooling for post-compromise operations. North Korean APTs are specifically noted as using React2Shell to deploy EtherRAT for espionage. Separately, North Korean APTs are mentioned as leveraging SSH-based tradecraft similar to other major actors by abusing the legitimate PuTTY client (e.g., plink.exe, pscp.exe) for stealthy lateral movement and data exfiltration in Windows environments, with forensic traces persisting in the PuTTY registry key HKCU\Software\SimonTatham\PuTTY\SshHostKeys. The content also describes a North Korean operator persona, “Trevor Greer,” exposed after the actor’s own machine was infected with information-stealing malware, revealing operational security failures and a broader ecosystem of fake identities and front companies. This persona is linked to the “Contagious Interview” campaign targeting Web3 developers via fake LinkedIn recruiter profiles, and to activity around the February 2025 ByBit cryptocurrency exchange compromise (reported as a $1.5B cryptocurrency extortion attributed to North Korean actors). Artifacts tied to this persona include trevorgreer9312@gmail[.]com (used to register Bybit-assessment[.]com) and domains associated with the ByBit operation such as getstockprice[.]com. The actor is described as using AI tools (ChatGPT, Quillbot) to support phishing/social engineering, engaging in fake employment/remote IT worker schemes via platforms such as Upwork/Freelancer under aliases (e.g., “Kenneth Debolt,” “Fabian Klein”), creating sham crypto entities (e.g., Block Bounce / blockbounce.xyz), and using legitimate services (e.g., Willo video interview platform) for reconnaissance and potential phishing infrastructure cloning.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Observables
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean APT groups exploited the React2Shell vulnerability to deploy EtherRAT for espionage operations, targeting organizations using Next.js and React Server Components.
North Korean APTs are known for using legitimate tools such as PuTTY for stealthy lateral movement, privilege escalation, and persistence, often blending their activity with normal administrative operations.
North Korean APT groups are conducting sophisticated cyber operations targeting the Web3 and cryptocurrency industry. Their campaigns involve creating fake personas and companies, infiltrating organizations as remote IT workers, and deploying information-stealing malware to compromise developer wallets and extort cryptocurrency. They leverage AI tools to improve their social engineering and operational effectiveness.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.