North Korean threat actor APT45 is known for both cyber espionage and ransomware operations.
Analyst brief
APT45, also known as GRASS NEPTUNE, is a North Korean cyber threat actor active since at least 2009. It primarily targets government agencies, defense industries, critical infrastructure, financial organizations, as well as nuclear research facilities, healthcare, and pharmaceutical companies. The group conducts both espionage and financially motivated campaigns, including ransomware operations, using a mix of publicly available tools, modified malware, and custom malware families. Defenders should focus on monitoring for targeted phishing attacks against these sectors and scrutinize network traffic for unusual RDP or C2 activity.
APT45
GRASS NEPTUNE
unknown
APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and defense industries, as well as financially-motivated operations, including ransomware development. APT45 has targeted critical infrastructure, financial organizations, nuclear research facilities, and healthcare and pharmaceutical companies. They use a mix of publicly available tools, modified malware, and custom malware families in their operations.
APT45 primarily targets government agencies, defense industries, critical infrastructure, financial organizations, nuclear research facilities, healthcare, and pharmaceutical companies.
What types of malicious activities does APT45 conduct?+
APT45 conducts both espionage and financially motivated campaigns, including ransomware operations. They use a mix of publicly available tools, modified malware, and custom malware families in their operations.