Darkseoul

Threat Actor updated 4 months ago (2024-05-04T20:19:31.972Z)
Download STIX
Preview STIX
DarkSeoul, also known as Onyx Sleet, Plutonium, and Andariel, is a threat actor group believed to be associated with the 110th Research Center. This group has been active since at least 2013, when it launched the DarkSeoul campaign, resulting in significant damage to thousands of systems in the financial sector and causing outages at the top three media companies in South Korea. The group targets defense and IT services organizations across the United States, South Korea, and India, frequently exploiting N-day vulnerabilities in their cyber attacks. The connection between DarkSeoul and the Lazarus group, another infamous advanced persistent threat actor, was made through the analysis of Dtrack samples. Initially, these samples were found as dropped payloads, encrypted with various droppers. However, using Kaspersky's Attribution Engine, cybersecurity researchers decrypted the final payload, revealing similarities with the 2013 DarkSeoul campaign. This discovery linked DarkSeoul to Lazarus, a group known for numerous cyberespionage and cyber sabotage operations. In conclusion, DarkSeoul poses a significant threat to global cybersecurity. Its association with the Lazarus group and its history of devastating cyber attacks, such as the 2013 campaign that severely impacted South Korea's financial sector and media companies, underscore the critical importance of remaining vigilant against this threat actor. Moreover, DarkSeoul's tendency to exploit N-day vulnerabilities highlights the need for robust and up-to-date security measures in defense and IT service organizations worldwide.
Description last updated: 2024-05-04T19:34:14.800Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Darkseoul Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CSO Online
a year ago
US sanctions four North Korean entities for global cyberattacks
MITRE
2 years ago
DTrack: previously unknown spy-tool by Lazarus hits financial institutions and research centers
CERT-EU
a year ago
North Korean Hackers Exploiting Recent TeamCity Vulnerability
Securityaffairs
a year ago
The US government sanctioned four entities and one individual for supporting cyber operations conducted by North Korea
MITRE
2 years ago
Hello! My name is Dtrack
CERT-EU
a year ago
The US sanctions entities linked to North Korean hackers