puNK-003puNK-003

Also known as: puNK-003

Known aliases
1

Profile

puNK-003 is a North Korean APT group known for deploying the Lilith RAT, a sophisticated C++ remote access trojan, and its AutoIt variant, CURKON, which functions as a downloader. The group primarily distributes malware through targeted phishing attacks using malicious LNK files. Analysis indicates that puNK-003 shares similarities with the KONNI group, particularly in the use of AutoIt scripts and specific coding functions. Key indicators of infection include unusual network activity and system slowdowns, with removal methods involving specialized antivirus software and manual techniques.

Aliases· 1

puNK-003

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNG0002
Actor
Earth Kitsune
Actor
APT.3102
Actor
APT3
Software
KONNI
Actor
DarkPink
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.