Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Experts Warn of Self-Funding North Korean Group APT43
Experts Warn of Self-Funding North Korean Group APT43
Security and Privacy

Experts Warn of Self-Funding North Korean Group APT43

May 24, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Mandiant has revealed a new North Korean APT group that uses crypto theft to fund its main goal of cyber-espionage for the Kim Jong-un regime.

APT43 is a prolific state actor whose publicly reported activities have sometimes been attributed to “Kimsuky” or “Thallium.” It is apparently linked to the Reconnaissance General Bureau (RGB), North Korea’s main foreign intelligence service. 

The group is notable for its prolific spear-phishing campaigns, supported by “aggressive” social engineering and spoofed domains/email addresses. The end goal is to harvest information aligned with foreign policy and nuclear security issues, although it switched to healthcare targets in 2021 likely as a result of the pandemic, Mandiant said.

Its main targets are South Korean and US-based government organizations, academics and think tanks focused on Korean geopolitical issues.

Read more on North Korean APT groups: Norway Seizes Millions in North Korean Crypto.

The group has created many spoofed and fake personas for its social engineering efforts, and sometimes also uses them as cover identities for buying operational tooling and infrastructure. Mandiant claimed that it engages targets over several weeks, in some cases tricking its victims into handing over information without even needing to deploy malware.

“We’ve seen the group posing as journalists to inquire into matters of intelligence interest to the DPRK regime, targeting European organizations,” explained Michael Barnhart, Mandiant principal analyst, Google Cloud.

“We’ve seen APT43 be extremely successful with these fake reporter emails, generating high success rates in eliciting a response from targets. This serves as a reminder to verify the addresses and identities of the people you’re speaking to.”

See also  Atomic Wallet Launches $1,000,000 Bug Bounty Program Months After Suffering Multi-Million Dollar Hack

Perhaps most interestingly, the group is self-funded, targeting individual victims rather than cryptocurrency exchanges to generate revenue for its state-focused operations, Mandiant claimed.

One such effort used a malicious Android app to target probable Chinese users looking for cryptocurrency loans. Mandiant has also tracked 10 million “phishing NFTs” delivered to crypto users on multiple blockchains since June 2022.

“By spreading their attack out across hundreds, if not thousands, of victims, their activity becomes less noticeable and harder to track than hitting one large target,” argued Mandiant principal analyst Joe Dobson.

“Their pace of execution, combined with their success rate, is alarming; especially when you consider that most funds stolen by DPRK cyber-operators are going back to the regime to fund its development of nuclear bombs.”

APT43 also uses hash rental and cloud mining services to launder stolen cryptocurrency into clean cryptocurrency.

“Imagine you stole millions of dollars in gold, and while everyone is looking for stolen gold, you pay silver miners with stolen gold to excavate silver for you. Similarly, APT43 deposits stolen cryptocurrency into various cloud mining services to mine for a different cryptocurrency,” explained Barnhart.

“For a small fee, DPRK walks away with untracked, clean currency to do as they wish. Based on our knowledge of this actor and the other associated groups, it is very likely that the other DPRK aligned APTs are using the same services to launder their illicit funds.”

Source link

APT43 Experts Group Korean North SelfFunding Warn
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Are Bitcoin bears not done yet? Analysts warn of a potential $53K BTC flush

June 11, 2026

Merck and Hashgraph Group launch Hedera-based product passport for EU compliance

June 11, 2026

Phunware to Showcase AI-Enabled Guest Intelligence Platform Enhancements at HITEC North America 2026

June 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Morph CEO on anticipated consumer-centric blockchain revolution

December 28, 2023

Decentralized File Storage Systems…What’s the Point?

December 2, 2023

“Bitcoin to $120k” – Standard Chartered Bank

July 11, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,795.000.25%
  • ethereumEthereum(ETH)$1,672.72-0.04%
  • tetherTether(USDT)$1.000.07%
  • binancecoinBNB(BNB)$604.61-0.13%
  • usd-coinUSDC(USDC)$1.000.02%
  • rippleXRP(XRP)$1.140.15%
  • solanaSolana(SOL)$67.391.01%
  • tronTRON(TRX)$0.3163441.27%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.07%
  • dogecoinDogecoin(DOGE)$0.0872190.81%