← All hunts high TLP:CLEAR

North Korean Exploitation and Destructive Impact

An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.

Based on research by Sekoia 2026-09-29 9 steps · 3 queries T1190 T1486

Brief

The Shift to Destruction

The Sekoia report Beyond Lazarus: How North Korea Organizes Its Cyber Operations (https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities) describes the infrastructure and intent behind North Korean operations. This hunt addresses a specific threat: the exploitation of public-facing assets to deliver ransomware or destructive payloads. By focusing on the transition from initial access to file-system impact, we move beyond simple alerts to identify the full kill chain.

Scoping the Attack Surface

The hunt begins by identifying vulnerable internet-facing hosts. The first query filters for critical vulnerabilities with known exploits or those listed in the CISA KEV catalog. This scoping ensures the behavioral analysis focuses on hosts with a clear, exploitable path to compromise.

Detecting Network Ingress

Once the hunt establishes a target list, it checks for successful inbound network traffic to sensitive management and database ports. This includes SSH, SMB, and common database listeners. By correlating this traffic with the previously identified vulnerable hosts, the hunt highlights external actors attempting to use the specific services likely targeted by North Korean groups.

Monitoring File System Impact

The hunt simultaneously monitors for spikes in file-system activity. It specifically looks for a high volume of file renames, which often indicates mass encryption. It also searches for the creation of known ransom note filenames. By using a fleet-wide baseline, the hunt filters out common files and highlights rare events that suggest a localized intrusion.

Triage and Response

An agent synthesizes the evidence from the vulnerability, network, and file system queries. It produces a per-host verdict that distinguishes between expected administrative maintenance and a live threat. If the agent finds concurrent evidence of ingress and encryption, the playbook provides an action to isolate the host immediately.

Blind Spots

This hunt requires detailed file-modification logging to detect encryption via renames. If an environment only logs file creation, an adversary could complete encryption before the hunt provides a signal. Additionally, the network analysis lacks integrated IP reputation; an analyst must manually verify if source IPs belong to known malicious infrastructure or legitimate external services.

How to Run the Hunt

This hunt is an open hunt.md playbook. You can import the design into Huntbase or any hunt.md-aware runtime to execute the queries and run the triage agent against your telemetry.

Steps

  1. Identify vulnerable internet-facing hosts

    Query · scoping

    Scope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.

    reads hb_vulnerability_findingsql
    SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'

    What a hit looks like. A list of hostnames with active, high-severity vulnerabilities. Silence indicates no known-exploitable vulnerabilities are currently tracked.

  2. Inbound connections to sensitive ports

    Query · detection candidate

    Identify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.

    reads hb_network_connectionsql
    SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name

    What a hit looks like. Connections from external IPs to sensitive internal listeners. Silence suggests no inbound traffic to these ports occurred during the lookback.

  3. Unusual file activity and ransom markers

    Query · baseline

    Detect mass file renames or the creation of known ransom note filenames that are rare across the fleet.

    reads hb_file_activitysql
    SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)

    What a hit looks like. Spikes in file renames or the presence of specific ransom note files. Rare occurrences on few hosts indicate possible intrusion.

  4. Triage intrusion evidence

    Agent triage

    Synthesize the vulnerability, network, and file system evidence to confirm a multi-stage attack.

  5. Evaluate threat risk

    Decision

    Route the investigation based on the triage agent's findings.

  6. Isolate compromised host

    Response action

    Prevent further data encryption or lateral movement by isolating confirmed infected hosts.

  7. Analyst forensic review

    Analyst task

    Verify the agent's findings and assess the extent of the damage.

  8. Close out

    Analyst task

    Document the hunt's findings and assess coverage.

Coverage

Scenario coverage

StageCoveredHow, or why not
Public-Facing Application Exploitation
T1190
Yes identify-vulnerable-targets, external-ingress-to-services
Ransomware Data Encryption
T1486
Yes unusual-file-modifications

Blind spots

  • Needs detailed EDR file modification logging. An intruder could encrypt files before detection if only file-creation events are captured. It would answer whether encryption is occurring on hosts with incomplete file activity logs.
  • Needs IP reputation enrichment for hb_network_connection. Legitimate but unusual remote access might be misidentified as a threat. It would answer whether the source IP is a known malicious proxy or state-actor infrastructure.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
ransom_note_patternslist[string]decrypt_instructions.html, recovery.txt, restore_files.txt, how_to_decrypt.htmlCommon filenames used for ransom notes; readme.txt is excluded due to high noise.
scope_hostslist[host]—Limit the hunt to specific hostnames; leave empty to scan the entire estate.
sensitive_portslist[string]22, 445, 1433, 3306, 5432, 5985, 5986Ports associated with management or databases often targeted by DPRK actors.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A rule might alert on a single ransom note; this hunt correlates pre-existing
  vulnerabilities with network ingress and fleet-wide file baselines to confirm a
  full kill-chain progression.
blind_spots:
- id: limited-file-telemetry
  question: whether encryption is occurring on hosts with incomplete file activity
    logs
  requires: detailed EDR file modification logging
  risk: An intruder could encrypt files before detection if only file-creation events
    are captured.
  stage: impact-data-encryption
- id: external-ip-reputation
  question: whether the source IP is a known malicious proxy or state-actor infrastructure
  requires: IP reputation enrichment for hb_network_connection
  risk: Legitimate but unusual remote access might be misidentified as a threat.
  stage: initial-access-vulnerability-exploitation
coverage:
- stage: initial-access-vulnerability-exploitation
  status: covered
  steps:
  - identify-vulnerable-targets
  - external-ingress-to-services
- stage: impact-data-encryption
  status: covered
  steps:
  - unusual-file-modifications
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: North Korean operations are a high-impact threat targeting financial
    assets and infrastructure. Detecting initial access on internet-facing assets
    is critical to preventing destructive encryption events.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting internet-facing vulnerabilities to gain initial
  access before encrypting user files to generate revenue or sabotage operations.
labels:
- hunt
- attack.t1190
- attack.t1486
- impact
- initial access
name: North Korean Exploitation and Destructive Impact
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  ransom_note_patterns:
    default:
    - decrypt_instructions.html
    - recovery.txt
    - restore_files.txt
    - how_to_decrypt.html
    description: Common filenames used for ransom notes; readme.txt is excluded due
      to high noise.
    type: list[string]
  scope_hosts:
    default: []
    description: Limit the hunt to specific hostnames; leave empty to scan the entire
      estate.
    type: list[host]
  sensitive_ports:
    default:
    - '22'
    - '445'
    - '1433'
    - '3306'
    - '5432'
    - '5985'
    - '5986'
    description: Ports associated with management or databases often targeted by DPRK
      actors.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing servers running SQL, SSH, or web applications.
  Use the identify-vulnerable-targets results to focus the behavioral queries.
references:
- name: 'Beyond Lazarus: How North Korea Organizes Its Cyber Operations'
  url: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
related:
- hunt: lateral-movement-via-rdp
  reason: This hunt focuses on initial access and impact; lateral movement via RDP
    requires separate authentication surface monitoring.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Public-Facing Application Exploitation
    observables:
    - Exploitation of web servers or databases
    - Connections to internet-accessible open sockets on SMB, SSH, or SQL ports
    - Exploitation of exposed VMware vCenter or OpenSLP services
    - Attempts to exploit software bugs or misconfigurations in Internet-facing hosts
    slug: initial-access-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Ransomware Data Encryption
    observables:
    - Encryption of common user files including Office documents, PDFs, images, and
      source code
    - WannaCry ransomware execution and file modification
    - Renaming of files with specific extensions or tags
    - Dropping of ransomware notes on local or remote drives
    slug: impact-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: North Korean cyber operations, orchestrated by state institutions like
    the GRIB and NIA, leverage asymmetric tactics including the exploitation of public-facing
    applications and destructive ransomware. These activities serve as a critical
    instrument for sanctions evasion and revenue generation, funding the regime's
    nuclear and missile programs.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# North Korean Exploitation and Destructive Impact

This hunt targets the dual-stage behavior of North Korean state-sponsored operations: initial access via public-facing application exploitation (T1190) followed by destructive file encryption (T1486). It identifies hosts with critical, exploitable vulnerabilities and correlates this scope with inbound network traffic to sensitive management ports and anomalous file system activity associated with ransomware deployment. An agent weighs the evidence across these surfaces to distinguish between administrative maintenance and a live intrusion.

## identify-vulnerable-targets
<!-- Identify vulnerable internet-facing hosts -->
Scope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames with active, high-severity vulnerabilities. Silence
  indicates no known-exploitable vulnerabilities are currently tracked.
reads:
- device_uid
- cve_uid
- severity
- severity_id
- status
- is_exploit_available
- is_kev
- resource_type
- collected_at
- hostname
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'
```

## parallel-behavior-check
<!-- Check for ingress and impact -->
parallel:
- → external-ingress-to-services
- → unusual-file-modifications
join: → triage-intrusion

## external-ingress-to-services
<!-- Inbound connections to sensitive ports -->
Identify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.

```sqlite target=network role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts, sensitive_ports=sensitive_ports)
~~~yaml
expected: Connections from external IPs to sensitive internal listeners. Silence suggests
  no inbound traffic to these ports occurred during the lookback.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_port
- process_name
- direction
- disposition
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name
```

## unusual-file-modifications
<!-- Unusual file activity and ransom markers -->
Detect mass file renames or the creation of known ransom note filenames that are rare across the fleet.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts, ransom_note_patterns=ransom_note_patterns)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Spikes in file renames or the presence of specific ransom note files. Rare
  occurrences on few hosts indicate possible intrusion.
prevalence:
  by: device_hostname
  key:
  - file_name
  rare_below: 3
reads:
- device_hostname
- file_name
- activity_name
- activity_id
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)
```

## triage-intrusion
<!-- Triage intrusion evidence -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-targets
- external-ingress-to-services
- unusual-file-modifications
max_iterations: 5
objective: Determine if the identified hosts show evidence of successful exploitation
  followed by file-system impact, distinguishing from legitimate administrative actions.
success_criteria: A detailed verdict citing specific rows from all queried surfaces.
tools:
- endpoint
- network
```

## evaluate-threat-risk
<!-- Evaluate threat risk -->
if~: "the triage verdict identifies at least one host with both suspicious inbound connections and active file encryption markers" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → analyst-forensic-review
unavailable: → analyst-forensic-review (blind_spot: limited-file-telemetry)
else: → close-out

## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host from the network after confirming the presence of ransomware-related artifacts.
```
→ analyst-forensic-review

## analyst-forensic-review
<!-- Analyst forensic review -->
```manual target=analyst
Examine the file renames and ransom note creation on the isolated host. Identify the originating process and any related network activity. Confirm if data exfiltration occurred prior to encryption.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
If no malicious activity was found, document the hosts examined and the state of their vulnerabilities for follow-up patching.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.