NICKEL HYATT
NICKEL HYATT is a subgroup of NICKEL ACADEMY assessed to have operated on behalf of the North Korean government since at least 2009. Its objectives include espionage and financial gain, and the group has also conducted destructive attacks and financial crime. Reported targeting includes financial institutions, defense contractors, government agencies, academic think tanks, cybersecurity vendors, and organizations supporting North Korean refugees. The group initially appeared focused on South Korea and later expanded targeting to Japan, the United States, and India. Observed tooling includes publicly available remote access trojans and custom malware including Rifle (Rifdoor), Valefor, UnitBot, and DTrack (also known as VinoSiren and Preft). Reported activity includes use of DTrack in 2019 against a nuclear power facility in India, use of DTrack in 2020 against a life sciences organization, and attempts during the COVID-19 pandemic to steal vaccine research data. Known associated aliases include Andariel, RIFLE Campaign, Silent Chollima, Dark Seoul, UN614, Stonefly, APT45, Onyx Sleet, and Jumpy Pisces.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- finance
- defense
- government
- academia
- cybersecurity
- energy
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.