Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Tracking State-Sponsored Threat Actors with OS...

Tracking State-Sponsored Threat Actors with OSINT: A DPRK Case Study

This talk was presented at ISCR 2026.

Avatar for JeongGak Lyu

JeongGak Lyu

August 28, 2026

More Decks by JeongGak Lyu

Other Decks in Technology

Transcript

  1. Cyber Threat Actor Categories Financial Gain Political & Social Causes

    Malice, Bribery, Negligence Espionage & Political Influence 2
  2. Attribution of Cyber Threat Actors • The Diamond Model as

    a practical framework https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf https://blog.talosintelligence.com/compartmentalized-threat-modeling/ • Collaboration, Initial Access Brokers (IABs), Operational Relay Boxes (ORBs), false flags, and AI increase attribution difficulty 3
  3. DPRK Operations Across All Categories Ransomware, Crypto Heists DDoS, Disruptive

    Attacks IT Worker Operations Espionage, Data Breaches, Disruptive Attacks 5
  4. CTI Lifecycle with LLM Agents • Running Hermes Agent on

    GPT-5.5 Publish Reports and Share Findings Identify Relationships and Draft Reports https://hermes-agent.nousresearch.com/ Monitor RSS Feeds, Mailing Lists, and Other Public Sources Summarize Reports, Extract and Enrich IoCs, Suggest Tags 6
  5. Results of OSINT Collection Annual Reporting Volume 792 800 627

    600 657 520 400 296 172 200 183 204 218 98 0 7 0 16 0 31 18 11 31 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026.8 7
  6. From 246 Names to 8 Clusters • Linking each new

    code name to the most closely related existing code name • Candidate clusters emerge through network analysis • 246 code names resolved into eight clusters 8
  7. Measuring the Cost of Naming Chaos • Coverage Curve: the

    share of reports retrievable when an analyst knows k code names - Single-name coverage ranges from 16% to 77% across clusters Coverage Curve by Cluster Cluster Kimsuky Single Names to Names to Name Reach 90% Reach 100% 77% 5 42 Konni 71% 2 12 Lazarus 65% 11 57 Andariel 61% 5 17 Bluenoroff 29% 13 34 Famous Chollima 27% 9 24 Scarcruft 16% 9 26 100 75 50 25 Kimsuky Bluenoroff 0 1 4 Lazarus Konni Scarcruft Andariel Famous Chollima 7 10 13 16 19 22 25 28 31 34 37 40 43 46 49 52 55 58 9
  8. The Shift to Financial Gain • Observed shift toward cryptocurrency

    theft and financial gain since 2015 Annual Incident Counts by Attack Motivation Targeted Sectors Overall 40 Other 8% Government 4% 30 Defense Healthcare 7% 4% 20 Technology 8% 10 0 2009 Espionage 2011 2013 Data Breach 2015 2017 Financial Gain 2019 Destruction 2021 2023 Supply Chain 2025 Cryptocurrency 49% Finance 20% Watering Hole 10
  9. Case Study: Linking a New Code Name • Expel publishes

    a report on Hexagonal Rodent - Report references Lazarus, Famous Chollima, and Contagious Interview D • Expel's Report A links to Report B through shared tags and IoCs • Reports C, D and E connect to B through IoCs and Contagious Interview C B A E ‣ Links to Contagious Interview https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/ https://lazarus.day/reports/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers-R7BvS/ 11
  10. Case Study: Attributing a New Incident • Supply chain attack

    on the JavaScript library Axios • Multiple vendors publish reports using different code names Vendor CrowdStrike Elastic Google(Mandiant) Microsoft Proofpoint Attribution Stardust Chollima REF9135 UNC1069 Sapphire Sleet TA444 ‣ Attributed to Bluenoroff https://lazarus.day/incidents/axios/ 12
  11. Threat Actors for Law Enforcement Primarily subject to investigation and

    arrest Often requiring diplomatic and policy responses 13
  12. Attribution for Law Enforcement • A recent joint advisory was

    unusually detailed, with technical data and IoCs published alongside CTI vendors - Attribution, however, was omitted • Value of in-house attribution capability and publishing attributed findings - Provides an industry verification baseline and a foundation for follow-up research and defensive measures https://police.go.kr/user/bbs/BD_selectBbs.do?q_bbsCode=1001&q_bbscttSn=20260730110134617 https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html https://www.yna.co.kr/view/AKR20260730121200017 14
  13. Closing • With a different dataset, the same method applies

    to other state sponsors • All data presented here is available at https://lazarus.day 15