Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors

Seongsu Park (Staff Threat Researcher · Gscaler)

DEF CON 33 · Day 1 · Main Stage

Overview

In his DEF CON talk, "Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors," Seongsu Park, a Staff Threat Researcher at Gscaler, delves into the increasingly complex landscape of North Korean state-sponsored cyber operations. Drawing on over a decade of experience tracking these elusive groups, Park highlights the significant challenges faced by threat intelligence professionals in accurately attributing cyberattacks. The presentation goes beyond traditional malware analysis, emphasizing the need for a comprehensive, full-context approach to understand the dynamic nature of these adversaries.

Watch on YouTube

Visual summary for Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors by Seongsu Park
Visual summary for Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors by Seongsu Park

Key moments

  1. 0:00 Talk introduction and speaker's experience
  2. 1:59 Explaining modern cyber attribution challenges
  3. 3:59 North Korea's growing cyber army numbers
  4. 5:10 2018: Lazarus Group's sub-cluster diversification
  5. 6:20 Distinct TTPs of Lazarus Group's sub-groups
  6. 7:00 Kimsuky Group's evolving clusters and objectives
  7. 8:50 Summary: Shared origin, diverse tactics and targets

Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors

Speakers: Seongsu Park, Staff Threat Researcher, Gscaler

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=j5gxdWd5sMg

Overview

In his DEF CON talk, "Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors," Seongsu Park, a Staff Threat Researcher at Gscaler, delves into the increasingly complex landscape of North Korean state-sponsored cyber operations. Drawing on over a decade of experience tracking these elusive groups, Park highlights the significant challenges faced by threat intelligence professionals in accurately attributing cyberattacks. The presentation goes beyond traditional malware analysis, emphasizing the need for a comprehensive, full-context approach to understand the dynamic nature of these adversaries.

Park's research underscores a critical shift in how North Korean advanced persistent threat (APT) groups operate. No longer monolithic entities, these actors are evolving through expansion, internal restructuring, inter-group collaboration, and the adoption of sophisticated obfuscation techniques, including the use of public tools and shared infrastructure. This talk is crucial for cybersecurity defenders, researchers, and policymakers alike, as it provides an up-to-date perspective on the adversary's evolving playbook, offering invaluable insights into their motivations, capabilities, and the defensive strategies required to counter them effectively.

The primary objective of this presentation is to share real-world experiences and case studies that illustrate the difficulties in attribution, particularly when dealing with well-resourced and highly adaptive state-sponsored actors like those from North Korea. By dissecting recent campaigns, Park demonstrates that superficial analysis often leads to misattribution, underscoring the necessity of deep, long-term investigation across the entire attack chain.

Background

▶ Watch: Talk introduction and speaker's experience (0:00)

Cyber threat intelligence (CTI) is the evidence-based knowledge about an adversary's motivations, tools, capabilities, and tactics, techniques, and procedures (TTPs). A critical component of CTI is attribution, the process of identifying who is behind a cyberattack. Historically, attribution was often a simpler task, with distinct malware families or infrastructure quickly linking an attack to a known group. However, as Seongsu Park explains, the modern threat landscape has made attribution profoundly challenging. Adversaries now intentionally employ false flags, share infrastructure, utilize advanced obfuscation techniques, leverage anonymization tools like VPNs and Tor, and frequently reuse public tools or TTPs from other groups.

North Korea's cyber capabilities have expanded dramatically over the past decade. The Lazarus Group, one of the most prominent North Korean APTs, first gained widespread notoriety for its 2014 attack on Sony Pictures, a landmark event demonstrating a nation-state's willingness to sabotage a private company. This was followed by their involvement in the 2017 WannaCry ransomware outbreak, which caused widespread global disruption. Initially focused on sabotage and defense sector espionage, Lazarus has increasingly pivoted towards financial gain, particularly targeting the cryptocurrency industry.

The scale of North Korea's cyber army has seen exponential growth. According to South Korean white papers, the number of North Korean cyber personnel rose from approximately 3,000 in 2013 to over 6,800 in 2018, and now exceeds 8,300. This dramatic increase, particularly around 2018, coincided with Kim Jong-un's announcement of the Pyongjin policy, emphasizing parallel development of nuclear weapons and the economy, with the economy becoming a top priority. This strategic shift has directly influenced the expansion and diversification of North Korea's cyber operations, leading to a more complex and fragmented threat landscape that demands sophisticated attribution methodologies.

Key Findings

▶ Watch: North Korea's growing cyber army numbers (3:59)

Seongsu Park's research reveals several critical evolutions in the tactics of North Korean cyber threat actors, each presenting unique attribution challenges:

  1. Expansion and Specialization of Actors: What were once considered monolithic groups like Lazarus or Kimsuky have expanded into multiple sub-clusters, each developing distinct TTPs, motivations, and target profiles. This internal segmentation allows for greater specialization and makes it difficult to track them as a single entity. For example, Lazarus has fragmented into groups like Diamond Sleet (defense sector), Moonstone Sleet, Citrine Sleet, and Jade Sleet (primarily cryptocurrency). Similarly, Kimsuky has diversified into clusters such as Baby Shark, Apple Seed, HTTP Spy, and Million OK, each employing different tools and targeting specific sectors or individuals, often for financial gain.
  1. Inter-Group Collaborations: Contrary to the perception of North Korean groups always acting as competitors, Park identified instances of explicit collaboration between different APTs to achieve shared objectives. A notable case involved Andariel and Kimsuky working in tandem on a supply chain attack targeting a South Korean cryptocurrency exchange. Andariel initiated the compromise with its Durian backdoor, then handed over access to Kimsuky, which proceeded to deploy its preferred toolset for data exfiltration and further compromise. This cooperation demonstrates a higher level of organizational maturity and resource sharing within the North Korean cyber ecosystem.
  1. Reshuffling and Reuse of Resources: The talk highlights instances where malware or tools initially attributed to one group are later observed being used by another, suggesting a "reshuffling" of resources, intellectual property, or even developers across different teams. The Pebble Dash malware, initially linked to Lazarus by CISA, was later found in campaigns exhibiting strong TTP overlaps with Kimsuky. This dynamic challenges static attribution based solely on malware signatures and necessitates long-term tracking of campaigns and infrastructure.
  1. Emergence of New Actors and Obfuscation: The continuous emergence of new, seemingly independent threat actors further complicates attribution. These groups often leverage readily available public tools (e.g., Donal Loader, CoatLet) and legitimate infrastructure (e.g., GitHub, free domain hosting) to obscure their origins. Attribution in these cases relies on subtle clues such as language preferences, working hours, and specific regional targeting, making definitive identification a protracted and challenging process. Park detailed a case where a new campaign used a combination of public tools and Korean-specific elements, making it difficult to link directly to known groups.

Technical Deep Dive

▶ Watch: 2018: Lazarus Group's sub-cluster diversification (5:10)

Park illustrated these key findings with detailed technical examples from his investigations:

Expansion of Actors: Lazarus and Kimsuky's Diversification

The Lazarus Group (also known as HIDDEN COBRA or APT38) has fractured into sub-groups, each with distinct operational focuses:

  • Diamond Sleet: Primarily targets the defense sector.
  • Moonstone Sleet, Citrine Sleet, Jade Sleet: Focus almost exclusively on the cryptocurrency industry, stealing funds from individuals and enterprises.

While these groups sometimes share code and infrastructure, their TTPs and motivations have diverged.

Similarly, the Kimsuky Group (also known as APT43 or Thallium) has diversified its clusters:

  • Baby Shark: Utilizes script-based malware, primarily PowerShell or Visual Basic Script.
  • Apple Seed and HTTP Spy: Employ C and C++-based malware. HTTP Spy is notable for being the only Kimsuky cluster observed using Go language for some of its malware.
  • Million OK: Focuses solely on financial profit through phishing kits to steal login credentials, often targeting individual investors in South Korea.

This specialization means that a TTP-based clustering approach is essential, as reacting to them as a single entity would be ineffective.

Inter-Group Collaboration: Andariel and Kimsuky

Park presented a late 2023 incident involving a South Korean cryptocurrency exchange, which was compromised via a supply chain attack.

  1. Initial Compromise: Threat actors tampered with the update server of an enterprise DRM software. During a normal update process, the software fetched a malicious file instead of a legitimate update.
  2. Trojanized Installer: This led to the implantation of a trojanized installer.
  3. Durian Backdoor: The final payload was Durian, a Go-language-based backdoor with intuitive functions like process command, hibernate, interable execute job, ars drive upload, and start. Initial analysis of Durian alone attributed the attack to the Andariel Group.
  4. Preliminary Tools Deployment: To maintain persistence and control, the attackers deployed additional preliminary tools:
  • proxyhload: A custom-made proxy tool.
  • ngrok: A well-known public tool used to bypass firewalls and NATs.
  • High-privilege accounts were established.
  • Chrome Desktop was installed for remote control.
  1. Kimsuky's Involvement: A deeper analysis of the full infection chain revealed the deployment of additional backdoors, specifically Apple Seed, and further account manipulation and Chrome Desktop usage, which are hallmarks of the Kimsuky Group.

Park concluded that Andariel initiated the attack, deployed the initial Durian backdoor, and then handed over control to Kimsuky, which subsequently deployed its preferred tools to achieve their shared objective. This highlights the necessity of analyzing the entire infection chain for accurate attribution.

Reshuffling of Resources: Pebble Dash Malware

This case, observed since August 2022, involved a .pif executable, a Windows executable that, upon execution, extracted and decrypted a decoy document and an additional payload. The payload was identified as Pebble Dash, a malware previously attributed to the Lazarus Group by CISA.

  • Initial Ambiguity: While Pebble Dash's configuration and execution structure resembled older Lazarus malware and the target was a defense sector entity in South Korea (a long-standing Lazarus target), certain aspects raised suspicion.
  • C2 Infrastructure Clue: The C2 domain used a free domain hosting service, p-ed.care, which is a service notoriously favored by the Kimsuky Group, not Lazarus.
  • Code Artifacts: An unused, strange string within Pebble Dash suggested potential reuse of code or tools, possibly due to a developer mistake.
  • Long-Term Tracking: Over two to three years, Park continuously monitored the campaign. In 2024, the variant heavily targeted job descriptions, initially in Germany, then switched back to South Korean defense and heavy industries. The initial infection vector consistently dropped HTTP Spy and Pebble Dash variants.
  • C2 Server Misconfiguration: A critical breakthrough occurred when a misconfigured C2 server was discovered. Accessing a resent.php file revealed email contents consistent with spear-phishing campaigns. Furthermore, a URL.txt file contained over 400 shortened URLs, which, when expanded, pointed to phishing links for login credentials of South Korean-specific portal services—a definitive tactic of the Kimsuky Group.

The conclusion was that while Lazarus might have initially developed or used Pebble Dash, the tool was either handed over to the Kimsuky Group, or the developers responsible for it moved to Kimsuky's operations. This demonstrates the fluid nature of tool ownership and the importance of dynamic observation over static attribution.

Emergence of New Actors: Public Tools and Subtle Clues

Following a significant political event in South Korea (declaration of martial law), a new spear-phishing campaign emerged five days later, using the event as a lure.

  1. Initial Vector: A .cpl file (Control Panel Item) was executed, fetching an additional archive from an attacker-controlled GitHub server.
  2. DLL Side-Loading: The archive contained a legitimate .exe file and a malicious version.dll file. Using DLL side-loading, the malicious DLL was executed.
  3. Information Stealer, Limited Functionality: The malicious DLL was identified as a known information stealer (Toa Stealer, introduced since mid-2020). However, the attackers only utilized its downloading functionality, not its information-stealing capabilities. Park noted that Toa Stealer is easily detected by most antivirus vendors, raising questions about its use by a sophisticated actor.
  4. Shellcode Execution: The infection procedure culminated in launching shellcode in memory via callback function hijacking.
  5. Public Tools: The shellcode was loaded using Donal Loader, a publicly available tool, which then decrypted and ran CoatLet, another public tool.
  6. Attribution Challenges: The extensive use of public tools made traditional attribution difficult. Park relied on subtle clues:
  • Linguistic Artifacts: The working path referred to "work" (Korean: 일, pronounced "il") rather than "job" or "fun," suggesting familiarity with Korean.
  • Software Usage: The use of Band, a Korean software, indicated a Korean-speaking context.
  • Time Zone Analysis: Aggregating malware compilation times and GitHub commit times suggested a working pattern in the GMT+8 and GMT+9 time zones (East China, South Korea, Japan).

While these clues strongly suggested a North Korean origin, the definitive group remained elusive, highlighting the challenge of attributing new campaigns that deliberately obscure their identity through the use of common tools and limited, context-dependent indicators.

Demo / Proof of Concept

▶ Watch: Kimsuky Group's evolving clusters and objectives (7:00)

This technical article is based on a conference talk that primarily focused on presenting research findings, case studies, and analytical methodologies rather than live demonstrations of attacks or tools. Seongsu Park's presentation meticulously detailed the infection chains, malware characteristics, and attribution challenges through high-level overviews and specific technical indicators derived from his extensive tracking of North Korean threat actors. Therefore, no live demo or proof of concept was conducted during the talk.

Defensive Implications

▶ Watch: Summary: Shared origin, diverse tactics and targets (8:50)

The evolving tactics of North Korean cyber threat actors necessitate a significant shift in defensive strategies. Defenders must move beyond simplistic, signature-based detections and embrace a more holistic, intelligence-driven approach:

  • Embrace TTP-Based Clustering: Traditional attribution to broad groups like "Lazarus" is no longer sufficient. Defenders must understand the distinct TTPs of the emerging sub-clusters (e.g., Diamond Sleet, Moonstone Sleet, Baby Shark, HTTP Spy) to tailor defenses effectively. A response designed for one sub-cluster's motivation and tools may be completely ineffective against another, even if they originate from the same umbrella organization.
  • Analyze the Full Infection Chain: As demonstrated by the Andariel/Kimsuky collaboration and the Pebble Dash reshuffling, attributing an attack based solely on the initial malware or a single stage of compromise is prone to error. Security teams must invest in capabilities to analyze the entire attack lifecycle, from initial access to command and control, lateral movement, and exfiltration, to uncover the full scope of adversary activity and potential multi-group involvement.
  • Anticipate Resource Reshuffling and Collaboration: Defenders should be aware that tools, infrastructure, and even personnel may be shared or transferred between different North Korean APTs. This means that an indicator of compromise (IOC) previously associated with one group might reappear in a campaign by another. Threat intelligence must track the evolution and reuse of tools over time, not just their initial attribution.
  • Account for Public Tool Usage: The increasing reliance on public tools (e.g., ngrok, Donal Loader) by sophisticated actors complicates detection and attribution. Defensive strategies should focus on detecting the misuse of these tools within an environment, alongside behavioral analysis that identifies anomalous processes or network connections, rather than solely blocking known malicious hashes.
  • Monitor for Subtle, Contextual Indicators: When direct technical attribution is obscured, subtle clues become crucial. Defenders operating in regions targeted by North Korea, particularly South Korea, should monitor for Korean-specific linguistic artifacts, software usage patterns (Band), and activity aligning with GMT+8/9 time zones. These indicators, when aggregated, can help narrow down potential adversaries.
  • Prioritize Collaboration and Information Sharing: Park emphasized the importance of cooperation between government agencies (like South Korea's NIS, CERT, National Police) and private sector organizations. Each entity possesses unique strengths and visibility, and sharing intelligence is paramount for building a comprehensive understanding of evolving threat landscapes and making accurate, full-context attributions.
  • Guard Against Attribution Bias: Analysts must consciously avoid the tendency to fit new campaigns or malware into known threat actor profiles. As Park confessed, this attribution bias can lead to significant mistakes. A critical, open-minded approach to new intelligence is essential.

Key Takeaways

  • North Korean cyber threat actors are no longer monolithic; they are expanding into specialized sub-clusters with distinct TTPs, motivations, and targets (e.g., Lazarus splitting into Diamond Sleet for defense, others for crypto; Kimsuky diversifying for espionage and financial gain).
  • Accurate attribution requires analyzing the full infection chain, not just initial malware or isolated incidents, as demonstrated by the Andariel/Kimsuky collaboration where initial malware analysis alone led to misattribution.
  • Inter-group collaboration and the reshuffling of tools and resources (e.g., Pebble Dash malware moving from Lazarus to Kimsuky's operational context) are becoming more common, challenging static attribution models.
  • The extensive use of public tools (e.g., ngrok, Donal Loader, CoatLet) by sophisticated actors, combined with shared infrastructure, significantly complicates traditional attribution efforts, requiring behavioral detection and contextual analysis.
  • Effective defense necessitates a shift from group-based attribution to TTP-based clustering to accurately understand and respond to the diverse tactics employed by these evolving adversaries.
  • Analysts must actively guard against attribution bias and prioritize comprehensive, full-context analysis, supported by strong cooperation and intelligence sharing between government and private sector entities.

About the Speaker(s)

Seongsu Park is a Staff Threat Researcher at Gscaler. With more than a decade of experience in the field of cyber threat intelligence, he has dedicated a significant portion of his career to tracking and analyzing the activities of North Korean threat actors. His unique position as the only Korean speaker on his team at Gscaler naturally led him to specialize in this challenging area. Park's insights are drawn directly from his extensive practical experience and research into the evolving TTPs, motivations, and organizational structures of these state-sponsored groups.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, practitioner-grade threat intel from someone who has clearly spent years in the weeds on DPRK attribution — not just aggregating public reporting but catching infrastructure misconfigs and tracking tool lineage across multi-year campaigns. The Andariel/Kimsuky handoff case and the Pebble Dash cross-attribution story are the kind of operational detail that separates real tracking work from recycled OSINT.

Heather Calloway (CISO) — SOLID

Seongsu Park brings real depth to North Korean APT tracking — the Andariel/Kimsuky handoff and the Pebble Dash reshuffling are genuinely instructive cases. But the talk stays inside the CTI analyst lane and never surfaces to the level where governance, accountability, or enterprise decision-making enters the picture.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33