APT43APT43

Also known as: APT43

Known aliases
1

Profile

• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities with aggressive social engineering tactics, especially against South Korean and U.S.-based government organizations, academics, and think tanks focused on Korean peninsula geopolitical issues. • In addition to its espionage campaigns, we believe APT43 funds itself through cybercrime operations to support its primary mission of collecting strategic intelligence. • The group creates numerous spoofed and fraudulent personas for use in social engineering, as well as cover identities for purchasing operational tooling and infrastructure. • APT43 has collaborated with other North Korean espionage operators on multiple operations, underscoring the major role APT43 plays in the regime’s cyber apparatus.

Aliases· 1

APT43

References

  1. https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage
  2. https://mandiant.widen.net/s/zvmfw5fnjs/apt43-report

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT45
Actor
APT42
Actor
APT37
Actor
APT41
Actor
APT33
Actor
TA444
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.