{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "North Korean operations are a high-impact threat targeting financial assets and infrastructure. Detecting initial access on internet-facing assets is critical to preventing destructive encryption events."
      },
      "name": "North Korean Exploitation and Destructive Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1486",
        "impact",
        "initial access"
      ],
      "related": [
        {
          "hunt": "lateral-movement-via-rdp",
          "reason": "This hunt focuses on initial access and impact; lateral movement via RDP requires separate authentication surface monitoring.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A rule might alert on a single ransom note; this hunt correlates pre-existing vulnerabilities with network ingress and fleet-wide file baselines to confirm a full kill-chain progression.",
      "coverage": [
        {
          "stage": "initial-access-vulnerability-exploitation",
          "steps": [
            "identify-vulnerable-targets",
            "external-ingress-to-services"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-data-encryption",
          "steps": [
            "unusual-file-modifications"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Public-Facing Application Exploitation",
            "slug": "initial-access-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Exploitation of web servers or databases",
              "Connections to internet-accessible open sockets on SMB, SSH, or SQL ports",
              "Exploitation of exposed VMware vCenter or OpenSLP services",
              "Attempts to exploit software bugs or misconfigurations in Internet-facing hosts"
            ]
          },
          {
            "name": "Ransomware Data Encryption",
            "slug": "impact-data-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Encryption of common user files including Office documents, PDFs, images, and source code",
              "WannaCry ransomware execution and file modification",
              "Renaming of files with specific extensions or tags",
              "Dropping of ransomware notes on local or remote drives"
            ]
          }
        ],
        "summary": "North Korean cyber operations, orchestrated by state institutions like the GRIB and NIA, leverage asymmetric tactics including the exploitation of public-facing applications and destructive ransomware. These activities serve as a critical instrument for sanctions evasion and revenue generation, funding the regime's nuclear and missile programs."
      },
      "severity": "high",
      "rationale": "Start with internet-facing servers running SQL, SSH, or web applications. Use the identify-vulnerable-targets results to focus the behavioral queries.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hostnames; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "sensitive_ports": {
          "type": "list[string]",
          "default": [
            "22",
            "445",
            "1433",
            "3306",
            "5432",
            "5985",
            "5986"
          ],
          "description": "Ports associated with management or databases often targeted by DPRK actors."
        },
        "ransom_note_patterns": {
          "type": "list[string]",
          "default": [
            "decrypt_instructions.html",
            "recovery.txt",
            "restore_files.txt",
            "how_to_decrypt.html"
          ],
          "description": "Common filenames used for ransom notes; readme.txt is excluded due to high noise."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities",
          "name": "Beyond Lazarus: How North Korea Organizes Its Cyber Operations"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-file-telemetry",
          "risk": "An intruder could encrypt files before detection if only file-creation events are captured.",
          "stage": "impact-data-encryption",
          "question": "whether encryption is occurring on hosts with incomplete file activity logs",
          "requires": "detailed EDR file modification logging"
        },
        {
          "id": "external-ip-reputation",
          "risk": "Legitimate but unusual remote access might be misidentified as a threat.",
          "stage": "initial-access-vulnerability-exploitation",
          "question": "whether the source IP is a known malicious proxy or state-actor infrastructure",
          "requires": "IP reputation enrichment for hb_network_connection"
        }
      ]
    },
    "name": "North Korean Exploitation and Destructive Impact",
    "description": "This hunt targets the dual-stage behavior of North Korean state-sponsored operations: initial access via public-facing application exploitation (T1190) followed by destructive file encryption (T1486). It identifies hosts with critical, exploitable vulnerabilities and correlates this scope with inbound network traffic to sensitive management ports and anomalous file system activity associated with ransomware deployment. An agent weighs the evidence across these surfaces to distinguish between administrative maintenance and a live intrusion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-vulnerability-exploitation",
            "steps": [
              "identify-vulnerable-targets",
              "external-ingress-to-services"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-data-encryption",
            "steps": [
              "unusual-file-modifications"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.",
        "blind_spots": [
          {
            "id": "limited-file-telemetry",
            "risk": "An intruder could encrypt files before detection if only file-creation events are captured.",
            "stage": "impact-data-encryption",
            "question": "whether encryption is occurring on hosts with incomplete file activity logs",
            "requires": "detailed EDR file modification logging"
          },
          {
            "id": "external-ip-reputation",
            "risk": "Legitimate but unusual remote access might be misidentified as a threat.",
            "stage": "initial-access-vulnerability-exploitation",
            "question": "whether the source IP is a known malicious proxy or state-actor infrastructure",
            "requires": "IP reputation enrichment for hb_network_connection"
          }
        ],
        "scoping_notes": "Start with internet-facing servers running SQL, SSH, or web applications. Use the identify-vulnerable-targets results to focus the behavioral queries.",
        "beyond_detection": "A rule might alert on a single ransom note; this hunt correlates pre-existing vulnerabilities with network ingress and fleet-wide file baselines to confirm a full kill-chain progression."
      }
    },
    {
      "id": "identify-vulnerable-targets",
      "type": "query",
      "label": "Identify vulnerable internet-facing hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'",
        "surface": "hb_vulnerability_finding",
        "description": "Scope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.",
        "expected_signal": "A list of hostnames with active, high-severity vulnerabilities. Silence indicates no known-exploitable vulnerabilities are currently tracked."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable internet-facing hosts",
        "reads": [
          "device_uid",
          "cve_uid",
          "severity",
          "severity_id",
          "status",
          "is_exploit_available",
          "is_kev",
          "resource_type",
          "collected_at",
          "hostname"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames with active, high-severity vulnerabilities. Silence indicates no known-exploitable vulnerabilities are currently tracked.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "external-ingress-to-services",
      "type": "query",
      "label": "Inbound connections to sensitive ports",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name",
        "surface": "hb_network_connection",
        "description": "Identify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.",
        "expected_signal": "Connections from external IPs to sensitive internal listeners. Silence suggests no inbound traffic to these ports occurred during the lookback."
      },
      "parents": [
        {
          "id": "identify-vulnerable-targets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Inbound connections to sensitive ports",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "dst_endpoint_port",
          "process_name",
          "direction",
          "disposition",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name",
        "silence": "not_evidence_of_absence",
        "expected": "Connections from external IPs to sensitive internal listeners. Silence suggests no inbound traffic to these ports occurred during the lookback.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "unusual-file-modifications",
      "type": "query",
      "label": "Unusual file activity and ransom markers",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)",
        "surface": "hb_file_activity",
        "description": "Detect mass file renames or the creation of known ransom note filenames that are rare across the fleet.",
        "expected_signal": "Spikes in file renames or the presence of specific ransom note files. Rare occurrences on few hosts indicate possible intrusion."
      },
      "parents": [
        {
          "id": "identify-vulnerable-targets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Unusual file activity and ransom markers",
        "reads": [
          "device_hostname",
          "file_name",
          "activity_name",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Spikes in file renames or the presence of specific ransom note files. Rare occurrences on few hosts indicate possible intrusion.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-intrusion",
      "type": "analytic",
      "label": "Triage intrusion evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "identify-vulnerable-targets",
          "external-ingress-to-services",
          "unusual-file-modifications"
        ],
        "objective": "Determine if the identified hosts show evidence of successful exploitation followed by file-system impact, distinguishing from legitimate administrative actions.",
        "description": "Synthesize the vulnerability, network, and file system evidence to confirm a multi-stage attack.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict of malicious, suspicious, or benign citing specific rows.",
        "success_criteria": "A detailed verdict citing specific rows from all queried surfaces."
      },
      "parents": [
        {
          "id": "external-ingress-to-services",
          "kind": "merge"
        },
        {
          "id": "unusual-file-modifications",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evaluate-threat-risk",
      "type": "checkpoint",
      "label": "Evaluate threat risk",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies at least one host with both suspicious inbound connections and active file encryption markers",
        "condition": "the triage verdict identifies at least one host with both suspicious inbound connections and active file encryption markers",
        "blind_spot": "limited-file-telemetry",
        "confidence": "high",
        "description": "Route the investigation based on the triage agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-intrusion"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further data encryption or lateral movement by isolating confirmed infected hosts.",
        "instructions": "Isolate the identified host from the network after confirming the presence of ransomware-related artifacts.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "evaluate-threat-risk",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and assess the extent of the damage.",
        "instructions": "Examine the file renames and ransom note creation on the isolated host. Identify the originating process and any related network activity. Confirm if data exfiltration occurred prior to encryption."
      },
      "parents": [
        {
          "id": "evaluate-threat-risk",
          "branch": "default"
        },
        {
          "id": "evaluate-threat-risk",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document the hunt's findings and assess coverage.",
        "instructions": "If no malicious activity was found, document the hosts examined and the state of their vulnerabilities for follow-up patching."
      },
      "parents": [
        {
          "id": "evaluate-threat-risk",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-forensic-review"
        }
      ]
    }
  ]
}