APT43 Report.pdf
ID: 4f32214c-edb4-4e83-a982-376878e71c8c
STIX ID: report--4f32214c-edb4-4e83-a982-376878e71c8c
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2023-03-29
Last Modified Date: 2023-03-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: This Mandiant report profiles APT43, a North Korean state-aligned cyber operator that conducts strategic espionage (targeting governments, academia, think tanks, and industry across South Korea, the U.S., Japan, and Europe) and supplements operations through financially-motivated cybercrime including cryptocurrency laundering; the report documents TTPs (spear-phishing, credential harvesting, spoofed domains), extensive malware tooling (LATEOP, LOGCABIN, PENCILDOWN, VENOMBITE, etc.), MITRE ATT&CK mappings, overlaps with other DPRK clusters, and sample IOCs to support detection and response.
