The Reconnaissance General Bureau (RGB) is North Korea's principal military intelligence organization and a central authority in the country's cyber apparatus. It is associated with intelligence operations, violent provocations, and disruptive cyber activity aligned with North Korea's asymmetric military strategy. North Korean cyber activity linked to the RGB has targeted South Korean military, government, financial, media, and other private-sector entities, as well as U.S. organizations. Operations associated with the broader apparatus have included distributed denial-of-service campaigns and destructive disk-wiping attacks, including attacks against South Korean banks and media organizations and the 2014 attack on Sony Pictures Entertainment. The RGB has been subject to international sanctions. Bureau 121 is commonly identified as a cyber-operational component within the broader North Korean intelligence and military structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as weaponizing AI for North Korean cyber operations, including deepfake-enabled fraud, identity deception, and adaptive malware operations.
North Korean state cyber operations and broader intelligence activities; described as controlling DPRK cyber capabilities and associated with disruptive attacks and provocations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.