north_korean_nation_state_actors
North Korean nation-state actors are primarily focused on cryptocurrency theft and intelligence gathering, with documented links to a $1.5 billion cryptocurrency theft in 2025. They employ a variety of tactics, including deploying ransomware (notably the FakePenny variant targeting aerospace and defense organizations), leveraging North Korean IT workers in remote jobs abroad to gain access to corporate systems and wallets, and conducting influence operations. These actors are also experimenting with generative AI to enhance phishing, influence campaigns, and malware development. Their operations are characterized by a blend of financial motivation and espionage, often targeting sectors such as cryptocurrency, aerospace, and defense. North Korean groups are known to collaborate with cybercriminal gangs and are increasingly integrating cyber operations into broader geopolitical strategies. No specific sub-group or alias is mentioned in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean nation-state actors focus on cryptocurrency theft and intelligence gathering, including using IT workers abroad to infiltrate corporate systems and digital wallets.
North Korean nation-state actors have developed and deployed a new ransomware variant, FakePenny, specifically targeting aerospace and defense sectors.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.