North Korean Exploitation and Destructive Impact
An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.
Based on research by Sekoia 2026-09-29 9 steps · 3 queries T1190 T1486
Brief
The Shift to Destruction
The Sekoia report Beyond Lazarus: How North Korea Organizes Its Cyber Operations (https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities) describes the infrastructure and intent behind North Korean operations. This hunt addresses a specific threat: the exploitation of public-facing assets to deliver ransomware or destructive payloads. By focusing on the transition from initial access to file-system impact, we move beyond simple alerts to identify the full kill chain.
Scoping the Attack Surface
The hunt begins by identifying vulnerable internet-facing hosts. The first query filters for critical vulnerabilities with known exploits or those listed in the CISA KEV catalog. This scoping ensures the behavioral analysis focuses on hosts with a clear, exploitable path to compromise.
Detecting Network Ingress
Once the hunt establishes a target list, it checks for successful inbound network traffic to sensitive management and database ports. This includes SSH, SMB, and common database listeners. By correlating this traffic with the previously identified vulnerable hosts, the hunt highlights external actors attempting to use the specific services likely targeted by North Korean groups.
Monitoring File System Impact
The hunt simultaneously monitors for spikes in file-system activity. It specifically looks for a high volume of file renames, which often indicates mass encryption. It also searches for the creation of known ransom note filenames. By using a fleet-wide baseline, the hunt filters out common files and highlights rare events that suggest a localized intrusion.
Triage and Response
An agent synthesizes the evidence from the vulnerability, network, and file system queries. It produces a per-host verdict that distinguishes between expected administrative maintenance and a live threat. If the agent finds concurrent evidence of ingress and encryption, the playbook provides an action to isolate the host immediately.
Blind Spots
This hunt requires detailed file-modification logging to detect encryption via renames. If an environment only logs file creation, an adversary could complete encryption before the hunt provides a signal. Additionally, the network analysis lacks integrated IP reputation; an analyst must manually verify if source IPs belong to known malicious infrastructure or legitimate external services.
How to Run the Hunt
This hunt is an open hunt.md playbook. You can import the design into Huntbase or any hunt.md-aware runtime to execute the queries and run the triage agent against your telemetry.
Steps
-
Identify vulnerable internet-facing hosts
Query · scopingScope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.
reads hb_vulnerability_findingsqlSELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'What a hit looks like. A list of hostnames with active, high-severity vulnerabilities. Silence indicates no known-exploitable vulnerabilities are currently tracked.
-
Inbound connections to sensitive ports
Query · detection candidateIdentify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.
reads hb_network_connectionsqlSELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_nameWhat a hit looks like. Connections from external IPs to sensitive internal listeners. Silence suggests no inbound traffic to these ports occurred during the lookback.
-
Unusual file activity and ransom markers
Query · baselineDetect mass file renames or the creation of known ransom note filenames that are rare across the fleet.
reads hb_file_activitysqlSELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)What a hit looks like. Spikes in file renames or the presence of specific ransom note files. Rare occurrences on few hosts indicate possible intrusion.
-
Triage intrusion evidence
Agent triageSynthesize the vulnerability, network, and file system evidence to confirm a multi-stage attack.
-
Evaluate threat risk
DecisionRoute the investigation based on the triage agent's findings.
-
Isolate compromised host
Response actionPrevent further data encryption or lateral movement by isolating confirmed infected hosts.
-
Analyst forensic review
Analyst taskVerify the agent's findings and assess the extent of the damage.
-
Close out
Analyst taskDocument the hunt's findings and assess coverage.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Public-Facing Application Exploitation T1190 |
Yes | identify-vulnerable-targets, external-ingress-to-services |
| Ransomware Data Encryption T1486 |
Yes | unusual-file-modifications |
Blind spots
- Needs detailed EDR file modification logging. An intruder could encrypt files before detection if only file-creation events are captured. It would answer whether encryption is occurring on hosts with incomplete file activity logs.
- Needs IP reputation enrichment for hb_network_connection. Legitimate but unusual remote access might be misidentified as a threat. It would answer whether the source IP is a known malicious proxy or state-actor infrastructure.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
ransom_note_patterns | list[string] | decrypt_instructions.html, recovery.txt, restore_files.txt, how_to_decrypt.html | Common filenames used for ransom notes; readme.txt is excluded due to high noise. |
scope_hosts | list[host] | — | Limit the hunt to specific hostnames; leave empty to scan the entire estate. |
sensitive_ports | list[string] | 22, 445, 1433, 3306, 5432, 5985, 5986 | Ports associated with management or databases often targeted by DPRK actors. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
Source
---
analysis: A rule might alert on a single ransom note; this hunt correlates pre-existing
vulnerabilities with network ingress and fleet-wide file baselines to confirm a
full kill-chain progression.
blind_spots:
- id: limited-file-telemetry
question: whether encryption is occurring on hosts with incomplete file activity
logs
requires: detailed EDR file modification logging
risk: An intruder could encrypt files before detection if only file-creation events
are captured.
stage: impact-data-encryption
- id: external-ip-reputation
question: whether the source IP is a known malicious proxy or state-actor infrastructure
requires: IP reputation enrichment for hb_network_connection
risk: Legitimate but unusual remote access might be misidentified as a threat.
stage: initial-access-vulnerability-exploitation
coverage:
- stage: initial-access-vulnerability-exploitation
status: covered
steps:
- identify-vulnerable-targets
- external-ingress-to-services
- stage: impact-data-encryption
status: covered
steps:
- unusual-file-modifications
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: North Korean operations are a high-impact threat targeting financial
assets and infrastructure. Detecting initial access on internet-facing assets
is critical to preventing destructive encryption events.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is exploiting internet-facing vulnerabilities to gain initial
access before encrypting user files to generate revenue or sabotage operations.
labels:
- hunt
- attack.t1190
- attack.t1486
- impact
- initial access
name: North Korean Exploitation and Destructive Impact
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
ransom_note_patterns:
default:
- decrypt_instructions.html
- recovery.txt
- restore_files.txt
- how_to_decrypt.html
description: Common filenames used for ransom notes; readme.txt is excluded due
to high noise.
type: list[string]
scope_hosts:
default: []
description: Limit the hunt to specific hostnames; leave empty to scan the entire
estate.
type: list[host]
sensitive_ports:
default:
- '22'
- '445'
- '1433'
- '3306'
- '5432'
- '5985'
- '5986'
description: Ports associated with management or databases often targeted by DPRK
actors.
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing servers running SQL, SSH, or web applications.
Use the identify-vulnerable-targets results to focus the behavioral queries.
references:
- name: 'Beyond Lazarus: How North Korea Organizes Its Cyber Operations'
url: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
related:
- hunt: lateral-movement-via-rdp
reason: This hunt focuses on initial access and impact; lateral movement via RDP
requires separate authentication surface monitoring.
relation: out-of-scope-alternative
scenario:
stages:
- name: Public-Facing Application Exploitation
observables:
- Exploitation of web servers or databases
- Connections to internet-accessible open sockets on SMB, SSH, or SQL ports
- Exploitation of exposed VMware vCenter or OpenSLP services
- Attempts to exploit software bugs or misconfigurations in Internet-facing hosts
slug: initial-access-vulnerability-exploitation
tactic: initial-access
techniques:
- T1190
- name: Ransomware Data Encryption
observables:
- Encryption of common user files including Office documents, PDFs, images, and
source code
- WannaCry ransomware execution and file modification
- Renaming of files with specific extensions or tags
- Dropping of ransomware notes on local or remote drives
slug: impact-data-encryption
tactic: impact
techniques:
- T1486
summary: North Korean cyber operations, orchestrated by state institutions like
the GRIB and NIA, leverage asymmetric tactics including the exploitation of public-facing
applications and destructive ransomware. These activities serve as a critical
instrument for sanctions evasion and revenue generation, funding the regime's
nuclear and missile programs.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
tlp: clear
type: investigation
---
# North Korean Exploitation and Destructive Impact
This hunt targets the dual-stage behavior of North Korean state-sponsored operations: initial access via public-facing application exploitation (T1190) followed by destructive file encryption (T1486). It identifies hosts with critical, exploitable vulnerabilities and correlates this scope with inbound network traffic to sensitive management ports and anomalous file system activity associated with ransomware deployment. An agent weighs the evidence across these surfaces to distinguish between administrative maintenance and a live intrusion.
## identify-vulnerable-targets
<!-- Identify vulnerable internet-facing hosts -->
Scope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames with active, high-severity vulnerabilities. Silence
indicates no known-exploitable vulnerabilities are currently tracked.
reads:
- device_uid
- cve_uid
- severity
- severity_id
- status
- is_exploit_available
- is_kev
- resource_type
- collected_at
- hostname
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'
```
## parallel-behavior-check
<!-- Check for ingress and impact -->
parallel:
- → external-ingress-to-services
- → unusual-file-modifications
join: → triage-intrusion
## external-ingress-to-services
<!-- Inbound connections to sensitive ports -->
Identify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.
```sqlite target=network role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts, sensitive_ports=sensitive_ports)
~~~yaml
expected: Connections from external IPs to sensitive internal listeners. Silence suggests
no inbound traffic to these ports occurred during the lookback.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_port
- process_name
- direction
- disposition
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name
```
## unusual-file-modifications
<!-- Unusual file activity and ransom markers -->
Detect mass file renames or the creation of known ransom note filenames that are rare across the fleet.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts, ransom_note_patterns=ransom_note_patterns)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Spikes in file renames or the presence of specific ransom note files. Rare
occurrences on few hosts indicate possible intrusion.
prevalence:
by: device_hostname
key:
- file_name
rare_below: 3
reads:
- device_hostname
- file_name
- activity_name
- activity_id
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)
```
## triage-intrusion
<!-- Triage intrusion evidence -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-targets
- external-ingress-to-services
- unusual-file-modifications
max_iterations: 5
objective: Determine if the identified hosts show evidence of successful exploitation
followed by file-system impact, distinguishing from legitimate administrative actions.
success_criteria: A detailed verdict citing specific rows from all queried surfaces.
tools:
- endpoint
- network
```
## evaluate-threat-risk
<!-- Evaluate threat risk -->
if~: "the triage verdict identifies at least one host with both suspicious inbound connections and active file encryption markers" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → analyst-forensic-review
unavailable: → analyst-forensic-review (blind_spot: limited-file-telemetry)
else: → close-out
## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host from the network after confirming the presence of ransomware-related artifacts.
```
→ analyst-forensic-review
## analyst-forensic-review
<!-- Analyst forensic review -->
```manual target=analyst
Examine the file renames and ransom note creation on the isolated host. Identify the originating process and any related network activity. Confirm if data exfiltration occurred prior to encryption.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
If no malicious activity was found, document the hosts examined and the state of their vulnerabilities for follow-up patching.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.