Reconnaissance General Bureau

Threat Actor updated 23 days ago (2024-11-29T13:53:06.913Z)
Download STIX
Preview STIX
The Reconnaissance General Bureau (RGB) is a North Korean intelligence agency known for its clandestine operations abroad. Its cyber activities, believed to be coordinated by the secretive organization, have been linked to various threat actors since at least 2014. Notable entities include the BeagleBoyz and Jumpy Pisces, which are state-sponsored threat groups associated with the RGB. The RGB's activities have evolved over time, shifting from espionage to targeting private companies, particularly those with limited intelligence value. This shift was observed by Symantec researchers in August and has been attributed to groups linked to the RGB, such as StoneFly. Several advanced persistent threat (APT) groups associated with the RGB have been active since 2018, including financially motivated entities that weaponize fake crypto platforms for attacks. Among these groups is Citrine Sleet, also known as AppleJeus, Labyrinth Chollima, UNC4736, and Hidden Cobra. This group, tracked within Bureau 121 of North Korea's RGB, was revealed by Microsoft in an August 30 blog post to have used CVE-2024-7971 in a campaign targeting crypto companies for financial gain. Other significant APT groups linked to the RGB include Kimsuky and Andariel, both of which have been involved in major hacking activities. The RGB's activities extend beyond cyberattacks and into illicit arms trade and ransomware incidents. For instance, an individual named Rim, who worked for the RGB, was indicted for participating in a conspiracy to target and hack computer networks of U.S. hospitals and other healthcare providers. The aim was to encrypt their electronic files, extort a ransom payment, launder those payments, and use the laundered proceeds to hack targets of interest to the North Korean regime. Court documents reveal that Rim and his co-conspirators, known in the private sector as 'Andariel,' 'Onyx Sleet,' and 'APT45,' laundered ransom payments through China-based facilitators. These funds were then used to purchase internet infrastructure for further hacking and exfiltration of sensitive defense and technology information from global entities.
Description last updated: 2024-10-30T16:02:48.149Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Andariel is a possible alias for Reconnaissance General Bureau. Andariel, a threat actor controlled by North Korea's military intelligence agency, the Reconnaissance General Bureau, has been actively conducting cyber espionage and ransomware operations. The group funds its activities through ransomware attacks primarily targeting U.S. healthcare entities. In som
6
Jumpy Pisces is a possible alias for Reconnaissance General Bureau. Jumpy Pisces, a North Korean state-sponsored malware group, has been identified as a key player in an unprecedented collaboration with an underground ransomware network. This marks a significant development in the cybersecurity landscape, as it's the first recorded instance of such cooperation betwe
2
Kimsuky is a possible alias for Reconnaissance General Bureau. Kimsuky is a threat actor group linked to North Korea, known for its malicious cyber activities with a particular focus on espionage. The group has been observed employing a variety of sophisticated tactics and techniques, including the use of malware such as TOGREASE, GREASE, and RandomQuery, which
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
State Sponso...
Korean
Phishing
Apt
Exploit
Reconnaissance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Lazarus Group Threat Actor is associated with Reconnaissance General Bureau. The Lazarus Group, a notorious threat actor attributed to North Korea, is renowned for its malicious activities aimed at furthering the country's objectives. This group has been implicated in several high-profile cyber-attacks, including an attack in Spain known as Operation DreamJob. The exploitatiUnspecified
2
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The Jumpy Vulnerability is associated with Reconnaissance General Bureau. Jumpy Pisces, a North Korean state-sponsored group, has been linked to a significant cybersecurity incident involving the Play ransomware group, also known as Fiddling Scorpius. This marks the first recorded collaboration between these two entities, raising concerns about an evolving threat landscapUnspecified
2
Source Document References
Information about the Reconnaissance General Bureau Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
InfoSecurity-magazine
2 months ago
DARKReading
2 months ago
Unit42
2 months ago
BankInfoSecurity
3 months ago
InfoSecurity-magazine
3 months ago
DARKReading
3 months ago
DARKReading
4 months ago
BankInfoSecurity
4 months ago
Securityaffairs
5 months ago
DARKReading
5 months ago
Flashpoint
5 months ago
InfoSecurity-magazine
8 months ago
CSO Online
2 years ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago