logo

APT43 Report.pdf

ID: 4f32214c-edb4-4e83-a982-376878e71c8c

STIX ID: report--4f32214c-edb4-4e83-a982-376878e71c8c

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2023-03-29

Last Modified Date: 2023-03-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: This Mandiant report profiles APT43, a North Korean state-aligned cyber operator that conducts strategic espionage (targeting governments, academia, think tanks, and industry across South Korea, the U.S., Japan, and Europe) and supplements operations through financially-motivated cybercrime including cryptocurrency laundering; the report documents TTPs (spear-phishing, credential harvesting, spoofed domains), extensive malware tooling (LATEOP, LOGCABIN, PENCILDOWN, VENOMBITE, etc.), MITRE ATT&CK mappings, overlaps with other DPRK clusters, and sample IOCs to support detection and response.