Why Malware Alone No Longer Identifies Attackers
When Park started in threat intelligence, identifying a malware sample was enough to name the group. That changed. Actors now plant false flags deliberately to mislead analysts. They share infrastructure across operations. They borrow public tools or copy techniques from competitor groups, and they route traffic through VPNs and anonymization services. The result: each of these habits erodes the signal that analysts rely on. Park’s four cases from the past decade show how each habit plays out in practice.
North Korea’s Cyber Army Grew From 3,000 to 8,300
South Korea’s annual defense white paper tracks North Korea’s cyber army. The count was 3,000 in 2013, 6,800 in 2018, and 8,300 in the most recent report. The 2018 doubling aligns with Kim Jong-un’s announcement of a strategic policy that elevated economic development alongside nuclear programs. That same year, new subclusters broke off from Lazarus: an early-2018 cluster hit Eastern Europe defense targets, and Apple Juice brought North Korean macOS malware for the first time. More subclusters appeared the same year.
Two Groups, One Victim: Andariel and Kimsuky Working Together
In late 2023, a South Korean cryptocurrency exchange was compromised through a supply chain attack. The attackers tampered with an enterprise DRM software’s update server, swapping the module hash so the software fetched a malicious file. That dropped Durian, a Go-based backdoor with full remote-control functions. Analyzing only Durian pointed to Andariel. But deeper in the chain, the attacker deployed AppleSeed (a Kimsuky tool), manipulated accounts, and installed Chrome Remote Desktop, all Kimsuky signatures. Two groups operated the same intrusion: Andariel gained access, then handed control to Kimsuky.
Pebble Dash Changes Hands: Tracing a Lazarus Tool to Kimsuky
In August 2022, Park found a PIF file that dropped Pebble Dash, a backdoor CISA attributed to Lazarus. The infection chain didn’t match Lazarus patterns. The C2 used a free Korean domain hosting service (.pe.kr) that Kimsuky had preferred for years. A YARA scan found other samples sharing the same decryption key. Park tracked the campaign’s C2 servers for two to three years and eventually found a misconfigured server exposing spear-phishing emails and over 400 shortened URLs targeting South Korean portals, a Kimsuky signature. Lazarus built Pebble Dash; Kimsuky was using it.
New Actors and the Danger of Confirmation Bias
Five days after South Korea’s president declared martial law in late 2024, a spear-phishing campaign hit South Korean targets using that content. The infection chain used only public tools: a CPL dropper, a side-loaded information stealer DLL, and Donut Loader for in-memory shellcode execution. Park found the attacker’s GitHub still live and extracted all artifacts. Build timestamps and commit times all clustered in GMT+8 to GMT+9, covering eastern China, South Korea, and Japan. He could not pin the campaign to any known North Korean group.
Notable Quotes
we always fail to respond to them because they each subcluster using a different TTP. Seongsu Park · ▶ 9:52
in order to understand the right attribution we should very carefully we should try to you understand the full infection chain Seongsu Park · ▶ 14:44
my confession is the I have some bias because when I found a new campaign or new mobile or something I tend to fit into that new things to known you know public thread actors so sometimes it make a many mistakes for me Seongsu Park · ▶ 24:54
Key Takeaways
- North Korea’s cyber army grew from 3,000 to 8,300 since 2013, with major cluster fragmentation starting in 2018.
- Andariel and Kimsuky jointly operated a 2023 supply chain intrusion, proving two groups can share a single victim.
- Analyzing only the first payload reliably produces wrong attribution; full infection chain review corrects it.
About the Speaker(s)
Seongsu Park (@unpacker) is a Staff Threat Researcher on the Zscaler APT Research team with over a decade of experience in malware analysis, threat intelligence, and incident response. His work has a heavy focus on tracking high-skilled North Korean threat actors and analyzing evolving attack vectors across the APAC region.