North Korean threat actors have expanded from distinct intrusion sets into overlapping cyber operations that mix espionage, financial theft, and targeted ransomware while reusing malware, infrastructure, and delivery tradecraft. Research across Lazarus, Kimsuky, APT43, and related DPRK-linked clusters shows campaigns against governments, think tanks, defense-linked individuals, banks, cryptocurrency firms, and South Korea-focused political and academic targets. Analysts tied these operations to spear-phishing with Word, HWP, ZIP, and password-protected archive lures; trojanized cryptocurrency software in the AppleJeus family; bank intrusions associated with Bluenoroff and SWIFT fraud; and crypto theft campaigns such as CryptoCore. Trellix also linked several narrowly targeted ransomware families to North Korea’s financial cyber apparatus, reinforcing the regime’s dual use of cyber operations for intelligence collection and revenue generation.
Recent reporting shows attribution is becoming harder because DPRK operators increasingly share tools and infrastructure across sub-clusters and adapt quickly to evade detection. Kimsuky campaigns used AppleSeed, AlphaSeed, GoldDragon, and DEEP#GOSU infection chains with cloud-hosted staging, mshta.exe, PowerShell, VBS, Dropbox, Google Docs, fake Blogspot pages, and strict victim-validation logic, while a later Korea-focused phishing operation combined Facebook, email, and Telegram to deliver obfuscated JSE malware. Separate analysis described a late-2023 crypto supply-chain intrusion delivering the Durian Golang RAT with signs of collaboration between Kimsuky and Andariel, and another case where PEBBLEDASH, long associated with Lazarus, appeared alongside Kimsuky-linked infrastructure. Researchers concluded that malware names alone no longer reliably identify the operator and that accurate attribution now depends on reconstructing the full intrusion chain, infrastructure, targeting, and strategic objective.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
50 events from the most recent confirmed update back to the earliest known activity.
Between March and April 2025, Genians detected a Kimsuky AppleSeed campaign in Korea using Facebook, email, and Telegram to target people involved in North Korea-related activities. The operation delivered password-protected EGG archives containing obfuscated JSE malware that dropped a decoy PDF and malicious DLL, then established persistence and encrypted C2 communications.
On 2024-12-08, a spear-phishing campaign used content related to South Korea’s 2024-12-03 martial law declaration. The infection chain used HWP lures, ZIP archives, DLL side-loading, Donut Loader shellcode, Quasar RAT, and Taurus Stealer code, and may represent a previously untracked DPRK-linked actor.
The DEF CON presentation states that ongoing campaigns targeting the defense sector in 2024 and 2025 used PebbleDash and httpSpy with job-themed social engineering lures. The activity further blurred attribution by combining Lazarus-origin tooling with Kimsuky-linked delivery tradecraft.
In late 2023, attackers manipulated a legitimate security product’s update mechanism to deliver a trojanized installer to a cryptocurrency exchange. The intrusion deployed Durian Golang RAT, HazyLoad, Ngrok, and remote-access tooling, and the presentation links the chain to both Kimsuky and Andariel.
AhnLab states that Kimsuky’s Golang-based AlphaSeed malware has been used in attacks since at least October 2022. AlphaSeed supports command execution and infostealing and can be deployed alongside AppleSeed.
The DEF CON presentation describes an August 2022 discovery of malware deploying PEBBLEDASH, a backdoor previously attributed by CISA to Lazarus. The case showed deviations from typical Lazarus tradecraft and included Kimsuky-linked infrastructure indicators.
AhnLab reports that since early 2022, AppleSeed has been created by a dropper rather than installed directly by JavaScript malware. The malware is installed as a DLL via regsvr32 with argument checks before persistence is established.
In early 2022, Kimsuky’s GoldDragon cluster attacked a media organization and a think-tank in South Korea. The campaign used spear-phishing, macro-enabled documents or Hangeul decoys, mshta, HTA and VBS payloads, and multi-stage victim-verifying C2 infrastructure.
In August 2020, DPRK operators targeted 28 United Nations officials in a spear-phishing campaign. CrowdStrike cites the operation as part of North Korea’s dual espionage and financial focus.
In August 2020, Israel thwarted a DPRK cyber attack against its defense industrial base. CrowdStrike includes the event in its chronology of North Korean operations.
ClearSky says its earlier June 2020 report described CryptoCore attacks targeting cryptocurrency exchanges in Israel, the United States, Europe, and Japan. The campaign focused on theft of cryptocurrency wallets and was later attributed to Lazarus with medium-high to high probability.
Trellix states that VHD ransomware surfaced in March 2020 and was widely attributed in the industry to DPRK hackers. The report links VHD to other small, targeted ransomware families associated with North Korea’s financial cyber apparatus.
The domain unioncrypto.vip, used to market and distribute the trojanized Union Crypto trading application, was created on 2019-06-05. CISA identifies the operation as part of the Lazarus AppleJeus malware family.
In March 2019, DPRK operators allegedly stole $7 million in cryptocurrency from DragonEx. CrowdStrike cites the theft as part of North Korea’s ongoing financial cyber operations.
From 2019 onward, DPRK allegedly engaged in targeted coercion and disinformation campaigns against media outlets. CrowdStrike presents this as a newer line of activity beyond theft and espionage.
VirusTotal reports that the oldest analyzed APT43-linked sample was uploaded in July 2018 from the United Kingdom. The telemetry set spans submissions from July 2018 through April 2023.
In February 2018, RICOCHET CHOLLIMA targeted government, infrastructure, and dissident entities. CrowdStrike marks this as part of DPRK’s transition to dual-focused operations.
In October 2017, DPRK operators targeted U.S. electric companies. CrowdStrike cites the activity as evidence of continued strategic targeting alongside financial operations.
In October 2017, DPRK operators allegedly stole $60 million from Taiwan’s Far Eastern International Bank. CrowdStrike includes the theft in its timeline of North Korean financial operations.
In April 2017, WannaCry propagated using the EternalBlue exploit. CrowdStrike says the ransomware infected about 200,000 systems worldwide.
In April 2017, South Korean cryptocurrency exchanges were compromised. CrowdStrike cites the intrusions as part of DPRK’s growing financially motivated activity.
Incident #2 began in January 2017 and affected multiple European financial institutions with Bluenoroff-associated malware. In one case on 2017-01-10, a victim visited the compromised Polish Financial Supervision Authority website, which loaded malicious content from sap.misapor.ch.
In December 2016, SWIFT-related bank heists targeted Bangladeshi Bank accounts. CrowdStrike presents this as part of DPRK’s shift toward currency-generation operations.
In November 2016, a packed version of a Lazarus-linked backdoor was uploaded from Poland and South Korea. Kaspersky assessed it was a precursor to attacks on Poland and other European countries.
In August 2016, 200 GB of South Korean Defense Ministry data was exfiltrated. CrowdStrike cites the theft as part of DPRK’s expanding cyber operations.
In August 2016, Kaspersky investigated an intrusion at a South East Asian bank where Lazarus-linked malware was found on a dedicated SWIFT Alliance server. The malware shared code and an identical RC4 key with Bangladesh-linked samples.
On 2016-02-04, attackers tampered with SWIFT-related systems in the broader Bangladesh Bank heist operation; Trellix describes the February 2016 heist as an attempted transfer of nearly $1 billion, and Kaspersky ties synchronized SWIFT tampering on that date to the campaign. The incident became a landmark DPRK-linked financial theft case.
From 2016 to 2017, DPRK operators allegedly used FASTCash malware to steal millions from ATMs across Asia and Africa. CrowdStrike says the activity enabled ATM jackpotting in more than 30 countries.
In December 2014, Korea Hydro & Nuclear Power exposed personally identifiable information and sensitive plant data. CrowdStrike lists the incident among DPRK-linked attacks on South Korean infrastructure.
In November 2014, the Sony Pictures compromise resulted in destroyed data and the public release of emails. Multiple references cite the incident as a major Lazarus- or DPRK-linked operation.
AhnLab reports that Kimsuky attacked a South Korean energy corporation in 2014. The event is presented as an early expansion of the group’s targeting beyond research institutes.
From March to August 2014, Seoul subway system networks were compromised. CrowdStrike includes the intrusion in its chronology of DPRK-linked operations.
In September 2013, attacks targeted the Korea Institute for Defense Analyses and Hyundai Merchant Marine. The incidents are cited as part of North Korea-linked activity against South Korean institutions.
In June 2013, a cyber espionage campaign targeted South Korea’s Ministry of Unification. CrowdStrike places this within DPRK’s early espionage-focused phase.
In March 2013, the Dark Seoul incident compromised two major broadcasters and three major banks in South Korea. Multiple references cite Dark Seoul as a Lazarus- or DPRK-linked operation.
AhnLab states that Kimsuky has been active since 2013 and initially targeted North Korea-related research institutes in South Korea. This marks the earliest anchored start of Kimsuky activity in the references.
In April 2011, a DDoS attack targeted South Korea’s Nonghyup Bank. The incident is listed among early North Korean-linked disruptive operations.
In March 2011, the Ten Days of Rain DDoS attacks targeted U.S. Forces Korea sites. The campaign is cited as part of DPRK’s early military-focused cyber activity.
In July 2009, North Korean-linked operators allegedly conducted DDoS attacks against 35 governmental sites in South Korea and the United States. CrowdStrike presents this as an early DPRK cyber operation.
Kaspersky and ClearSky state that Lazarus Group activity dates back to at least 2009. This marks the earliest anchored start of the actor’s known operations in the references.
Zscaler ThreatLabZ presented research arguing that North Korean cyber operations have evolved into umbrella organizations with specialized sub-clusters, shared tooling, and collaborative operations. The presentation used Lazarus, Kimsuky, the late-2023 crypto supply-chain intrusion, the PEBBLEDASH case, and the December 2024 campaign to illustrate growing attribution complexity.
Securelist analyzed Kimsuky’s GoldDragon cluster and described a multi-stage C2 architecture that verified victims using email parameters, forwarded IP validation, OS and user-agent filtering, and per-victim fake Blogspot pages. The report tied the infrastructure to early 2022 attacks on South Korean political, diplomatic, academic, media, and think-tank targets.
Trellix assessed with high confidence that VHD, BEAF, PXJ, ZZZZ, and CHiCHi ransomware activity was linked to DPRK-affiliated hackers tied to APT38 or Unit 180. The report characterized the campaigns as narrowly targeted APAC revenue-generation operations rather than broad criminal extortion.
ClearSky concluded with high probability that Lazarus conducted the multi-year CryptoCore campaign against cryptocurrency exchanges worldwide. The report correlated shared indicators, nearly identical VBS C2 scripts, malware overlaps, and YARA matches across prior vendor research.
Kaspersky concluded that a Lazarus subgroup it named Bluenoroff focuses on attacks against banks and financial manipulation. Its forensic work linked SWIFT-supporting system intrusions at banks in Asia and Europe to Lazarus malware and tradecraft.
AhnLab documented Kimsuky’s continued use of AppleSeed, newer anti-analysis checks, increased use of %APPDATA%, and the AlphaSeed Golang variant. The report also noted continued use of Meterpreter, VNC-based tooling, and growing use of Chrome Remote Desktop.
Securonix reported the DEEP#GOSU campaign, likely associated with Kimsuky, using ZIP attachments with disguised PDF LNK files, Dropbox-hosted payloads, in-memory .NET loading, and the TruRat/TutRat RAT. Later stages added scheduled-task persistence, encrypted Dropbox exfiltration, keylogging, and clipboard monitoring.
VirusTotal analyzed malware telemetry associated with APT43 using IOCs previously attributed by Mandiant. The post highlighted sample activity from July 2018 through April 2023 and emphasized targeting of U.S. and South Korean government, research, and business entities.
CISA published a malware analysis report on the AppleJeus Union Crypto campaign, describing trojanized Windows and macOS cryptocurrency trading applications distributed via unioncrypto.vip. The report says the malware profiled hosts, established persistence, and could retrieve a second-stage payload for command execution and file operations.
Unit 42 disclosed a malware cluster targeting Korean-language speakers using Samsung devices, with links to Operation Blockbuster, HiddenCobra, and Bangladesh SWIFT malware. The infection chain used JAVAC.EXE to serve JavaScript and nested APK payloads culminating in the Android backdoor object.apk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcetrellix.com
Open sourcegenians.co.kr
Open sourcemedia.defcon.org
Open sourceunit42.paloaltonetworks.com
Open sourcei.blackhat.com
Open sourcemedia.kasperskycontenthub.com
Open sourceclearskysec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.