Reconnaissance General Bureau Rgb

Threat Actor updated 2 months ago (2024-10-03T03:01:00.006Z)
Download STIX
Preview STIX
The Reconnaissance General Bureau (RGB) of the Korean People's Army is a significant threat actor in global cybersecurity, housing various hacking groups under its control. These groups include well-known entities such as "Lazarus Group," "Bluenoroff," and "Andariel," identified by Executive Order 13722 as agencies or controlled entities of the Government of North Korea due to their relationship with RGB. Another notable group, known publicly as Andariel, along with Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, are part of the RGB 3rd Bureau based in Pyongyang and Sinuiju, associated with cyber espionage activity. The Pyongyang University of Automation, sanctioned by the US, is a key institution for training these malicious cybersecurity actors who often work in units subordinate to the RGB. Multiple incidents involving RGB have been reported. In one case, an indictment filed in the U.S. District Court in Los Angeles alleges that Jon Chang Hyok, Kim Il, and Park Jin Hyok, members of RGB, engaged in criminal hacking. Stonefly, another RGB group, launched attacks on three US organizations shortly after the Department of Justice took action against them. Furthermore, an advisory from the FBI, NSA, and the US State Department stated that Kimsuky, operating under RGB, sent spoofed emails to high-profile individuals across various sectors, aligning with the objectives of RGB, North Korea's primary foreign intelligence agency. Kimsuky, also known as APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet, Nickel Kimball, and Velvet Chollima, is a significant element operating under RGB, which also houses the Lazarus Group. Active since 2012, Kimsuky is recognized as a malicious entity conducting cyber activities associated with advanced persistent threats. The group was implicated in a conspiracy to target and hack U.S. hospitals and healthcare providers, encrypt their files, extort ransoms, launder those payments, and use the laundered proceeds to hack targets of interest to the North Korean regime.
Description last updated: 2024-10-03T02:16:43.448Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Andariel is a possible alias for Reconnaissance General Bureau Rgb. Andariel, a threat actor controlled by North Korea's military intelligence agency, the Reconnaissance General Bureau, has been actively conducting cyber espionage and ransomware operations. The group funds its activities through ransomware attacks primarily targeting U.S. healthcare entities. In som
3
Apt43 is a possible alias for Reconnaissance General Bureau Rgb. APT43, also known as Kimsuky, is a North Korean Advanced Persistent Threat (APT) group that has been active since at least 2013. The group is known for its intelligence collection activities and using cybercrime to fund espionage. It has been linked to several aliases including Springtail, ARCHIPELA
2
Kimsuky is a possible alias for Reconnaissance General Bureau Rgb. Kimsuky, also known as Springtail, ARCHIPELAGO, Black Banshee, Thallium, Velvet Chollima, and APT43, is a North Korea-linked Advanced Persistent Threat (APT) group that has been active since it was first spotted by Kaspersky researchers in 2013. The group is notorious for its cyber espionage activit
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Reconnaissance
State Sponso...
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Reconnaissance General Bureau Rgb Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
2 months ago
DARKReading
2 months ago
Unit42
2 months ago
Unit42
2 months ago
InfoSecurity-magazine
3 months ago
Flashpoint
4 months ago
CISA
4 months ago
CISA
4 months ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CSO Online
2 years ago
CSO Online
a year ago
CERT-EU
a year ago
MITRE
2 years ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
2 years ago
CERT-EU
a year ago