Threat Intelligence Tarot
Vol. II · 126
North Korea (Reconnaissance General Bureau)
G1004★★★★★
risk 4/5
✦ The Hungry Banshee ✦
APT43
Black Banshee · Kimsuky-adjacent · Thallium-related · Emerald Sleet
South Korean policy researchersUS think tanksCryptocurrency exchangesKorean Peninsula academia
Active since ~2018 · Strategic intelligence, Cryptocurrency theft, Nuclear program funding
The Hungry Banshee feeds the regime that fed it. Each stolen briefing, each drained wallet, becomes calories for a state that learned long ago that intelligence and theft are the same skill, applied differently.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Persona-based engagement of North Korea policy researchers
- ◆Mandiant APT43 disclosure (March 2023)
- ◆Cryptocurrency theft cycles funding regime operations
- ◆Long-term cultivation of think tank and academic relationships
Defenses
- ▸Phishing-resistant MFA on think tank and academic accountsNIST SP 800-63B ↗
- ▸Out-of-band verification of unsolicited researcher engagementsNIST CSF: PR.AT ↗
- ▸Cryptocurrency exchange employee endpoint hardeningCIS Control 4 ↗
- ▸Cloud storage exfiltration detection (Drive/OneDrive anomalies)NIST CSF: DE.CM ↗
Reversed: Their Weakness
Researcher-targeted phishing-resistant authentication and persona verification (out-of-band confirmation of new contacts) starve this operator of its preferred currency.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.