CyberzSOC

Publication detail
← Back to advisories & guidance

North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs ↗ source

July 25, 2024 NSA Alert
Co-sealed by: CISA, CNMF, DC3, FBI, NCSC-UK, NIS, NSA

Summary

The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified technical information and intellectual property to advance the regime’s military and nuclear programs and ambitions. The authoring agencies believe the group and the cyber techniques remain an ongoing threat to various industry sectors worldwide, including but not limited to entities in their respective countries, as well as in Japan and India. RGB 3rd Bureau actors fund their espionage activity through ransomware operations against U.S. healthcare entities. The actors gain initial access through widespread exploitation of web servers through known vulnerabilities in software, such as Log4j, to deploy a web shell and gain access to sensitive information and applications for further exploitation. The actors then employ standard system discovery and enumeration techniques, establish persistence using Scheduled Tasks, and perform privilege escalation using common credential stealing tools such as Mimikatz.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2023-46604
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2022-27925

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2022-22947 10.0 Critical VMware Spring Cloud Gateway Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
CVE-2023-35078 10.0 Critical Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated…
CVE-2023-46604 10.0 Critical Apache ActiveMQ Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run sh…
CVE-2022-24663 9.9 Critical Alexander Fuchs PHP Everywhere PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authent…
CVE-2022-24664 9.9 Critical Alexander Fuchs PHP Everywhere PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user a…
CVE-2022-24665 9.9 Critical Alexander Fuchs PHP Everywhere PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit p…
CVE-2019-0708 9.8 Critical Microsoft Remote Desktop Services Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker …
CVE-2019-7609 9.8 Critical Elastic Kibana Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
CVE-2021-20028 9.8 Critical SonicWall Secure Remote Access (SRA) SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2021-20038 9.8 Critical SonicWall SMA 100 Appliances SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code executi…
CVE-2022-22965 9.8 Critical VMware Spring Framework Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-24990 9.8 Critical TerraMaster TerraMaster OS TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.
CVE-2022-41352 9.8 Critical Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user a…
CVE-2022-47966 9.8 Critical Zoho ManageEngine Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party depend…
CVE-2023-25690 9.8 Critical Apache Software Foundation Apache HTTP Server Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec…
CVE-2023-28771 9.8 Critical Zyxel Multiple Firewalls Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute…
CVE-2023-33010 9.8 Critical Zyxel Multiple Firewalls Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing functio…
CVE-2023-33246 9.8 Critical Apache RocketMQ Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An…
CVE-2023-34362 9.8 Critical Progress MOVEit Transfer Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Tr…
CVE-2023-3519 9.8 Critical Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2023-42793 9.8 Critical JetBrains TeamCity JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-2868 9.4 Critical Barracuda Networks Email Security Gateway (ESG) Appliance Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote …
CVE-2023-27997 9.2 Critical Fortinet FortiOS and FortiProxy SSL-VPN Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to exe…
CVE-2021-44142 8.8 High Samba Samba The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperabilit…
CVE-2022-22005 8.8 High Microsoft Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-3079 8.8 High Google Chromium V8 Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
CVE-2023-32315 8.6 High Ignite Realtime Openfire Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire A…
CVE-2021-36955 7.8 High Microsoft Windows Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-43226 7.8 High Microsoft Windows Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass…
CVE-2022-30190 7.8 High Microsoft Windows A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who succ…
CVE-2021-41773 7.5 High Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf…
CVE-2022-24785 7.5 High moment moment Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (serve…
CVE-2023-32784 7.5 High n/a n/a In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer …
CVE-2022-27925 7.2 High Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files …
CVE-2023-0669 7.2 High Fortra GoAnywhere MFT Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due t…
CVE-2023-21932 7.2 High Oracle Corporation Hospitality OPERA 5 Property Services Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported versio…
CVE-2019-15637 7.1 High n/a n/a Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This…
CVE-2022-21882 7.0 High Microsoft Win32k Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2017-4946 — VMware vRealize Operations for Horizon (V4H) The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could r…
CVE-2021-3018 — n/a n/a ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/prin…
CVE-2021-40684 — n/a n/a Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which all…
CVE-2021-45837 — n/a n/a It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted in…
CVE-2022-25064 — n/a n/a TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.