---
analysis: A rule might alert on a single ransom note; this hunt correlates pre-existing
  vulnerabilities with network ingress and fleet-wide file baselines to confirm a
  full kill-chain progression.
blind_spots:
- id: limited-file-telemetry
  question: whether encryption is occurring on hosts with incomplete file activity
    logs
  requires: detailed EDR file modification logging
  risk: An intruder could encrypt files before detection if only file-creation events
    are captured.
  stage: impact-data-encryption
- id: external-ip-reputation
  question: whether the source IP is a known malicious proxy or state-actor infrastructure
  requires: IP reputation enrichment for hb_network_connection
  risk: Legitimate but unusual remote access might be misidentified as a threat.
  stage: initial-access-vulnerability-exploitation
coverage:
- stage: initial-access-vulnerability-exploitation
  status: covered
  steps:
  - identify-vulnerable-targets
  - external-ingress-to-services
- stage: impact-data-encryption
  status: covered
  steps:
  - unusual-file-modifications
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: North Korean operations are a high-impact threat targeting financial
    assets and infrastructure. Detecting initial access on internet-facing assets
    is critical to preventing destructive encryption events.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting internet-facing vulnerabilities to gain initial
  access before encrypting user files to generate revenue or sabotage operations.
labels:
- hunt
- attack.t1190
- attack.t1486
- impact
- initial access
name: North Korean Exploitation and Destructive Impact
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  ransom_note_patterns:
    default:
    - decrypt_instructions.html
    - recovery.txt
    - restore_files.txt
    - how_to_decrypt.html
    description: Common filenames used for ransom notes; readme.txt is excluded due
      to high noise.
    type: list[string]
  scope_hosts:
    default: []
    description: Limit the hunt to specific hostnames; leave empty to scan the entire
      estate.
    type: list[host]
  sensitive_ports:
    default:
    - '22'
    - '445'
    - '1433'
    - '3306'
    - '5432'
    - '5985'
    - '5986'
    description: Ports associated with management or databases often targeted by DPRK
      actors.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing servers running SQL, SSH, or web applications.
  Use the identify-vulnerable-targets results to focus the behavioral queries.
references:
- name: 'Beyond Lazarus: How North Korea Organizes Its Cyber Operations'
  url: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
related:
- hunt: lateral-movement-via-rdp
  reason: This hunt focuses on initial access and impact; lateral movement via RDP
    requires separate authentication surface monitoring.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Public-Facing Application Exploitation
    observables:
    - Exploitation of web servers or databases
    - Connections to internet-accessible open sockets on SMB, SSH, or SQL ports
    - Exploitation of exposed VMware vCenter or OpenSLP services
    - Attempts to exploit software bugs or misconfigurations in Internet-facing hosts
    slug: initial-access-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Ransomware Data Encryption
    observables:
    - Encryption of common user files including Office documents, PDFs, images, and
      source code
    - WannaCry ransomware execution and file modification
    - Renaming of files with specific extensions or tags
    - Dropping of ransomware notes on local or remote drives
    slug: impact-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: North Korean cyber operations, orchestrated by state institutions like
    the GRIB and NIA, leverage asymmetric tactics including the exploitation of public-facing
    applications and destructive ransomware. These activities serve as a critical
    instrument for sanctions evasion and revenue generation, funding the regime's
    nuclear and missile programs.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# North Korean Exploitation and Destructive Impact

This hunt targets the dual-stage behavior of North Korean state-sponsored operations: initial access via public-facing application exploitation (T1190) followed by destructive file encryption (T1486). It identifies hosts with critical, exploitable vulnerabilities and correlates this scope with inbound network traffic to sensitive management ports and anomalous file system activity associated with ransomware deployment. An agent weighs the evidence across these surfaces to distinguish between administrative maintenance and a live intrusion.

## identify-vulnerable-targets
<!-- Identify vulnerable internet-facing hosts -->
Scope the hunt to hosts with critical vulnerabilities that have known exploits or are in the CISA KEV catalog, mapping them to hostnames.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames with active, high-severity vulnerabilities. Silence
  indicates no known-exploitable vulnerabilities are currently tracked.
reads:
- device_uid
- cve_uid
- severity
- severity_id
- status
- is_exploit_available
- is_kev
- resource_type
- collected_at
- hostname
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT v.device_uid, d.hostname AS device_hostname, v.cve_uid, v.severity, v.collected_at FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid AND v.provider = d.provider WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND (v.is_exploit_available = 'true' OR v.is_kev = 'true') AND v.resource_type = 'device'
```

## parallel-behavior-check
<!-- Check for ingress and impact -->
parallel:
- → external-ingress-to-services
- → unusual-file-modifications
join: → triage-intrusion

## external-ingress-to-services
<!-- Inbound connections to sensitive ports -->
Identify successful inbound network traffic to database and management ports from external sources, potentially representing exploitation.

```sqlite target=network role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts, sensitive_ports=sensitive_ports)
~~~yaml
expected: Connections from external IPs to sensitive internal listeners. Silence suggests
  no inbound traffic to these ports occurred during the lookback.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_port
- process_name
- direction
- disposition
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as connection_count FROM hb_network_connection WHERE direction = 'inbound' AND disposition = 'Allowed' AND instr(',' || '{{sensitive_ports}}' || ',', ',' || CAST(dst_endpoint_port AS TEXT) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, dst_endpoint_port, process_name
```

## unusual-file-modifications
<!-- Unusual file activity and ransom markers -->
Detect mass file renames or the creation of known ransom note filenames that are rare across the fleet.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts, ransom_note_patterns=ransom_note_patterns)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Spikes in file renames or the presence of specific ransom note files. Rare
  occurrences on few hosts indicate possible intrusion.
prevalence:
  by: device_hostname
  key:
  - file_name
  rare_below: 3
reads:
- device_hostname
- file_name
- activity_name
- activity_id
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, file_name, activity_name, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (activity_id = 5 OR (activity_id = 1 AND instr(',' || '{{ransom_note_patterns}}' || ',', ',' || LOWER(file_name) || ',') > 0)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, file_name, activity_name HAVING (activity_id = 5 AND event_count > 50) OR (activity_id = 1)
```

## triage-intrusion
<!-- Triage intrusion evidence -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-targets
- external-ingress-to-services
- unusual-file-modifications
max_iterations: 5
objective: Determine if the identified hosts show evidence of successful exploitation
  followed by file-system impact, distinguishing from legitimate administrative actions.
success_criteria: A detailed verdict citing specific rows from all queried surfaces.
tools:
- endpoint
- network
```

## evaluate-threat-risk
<!-- Evaluate threat risk -->
if~: "the triage verdict identifies at least one host with both suspicious inbound connections and active file encryption markers" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → analyst-forensic-review
unavailable: → analyst-forensic-review (blind_spot: limited-file-telemetry)
else: → close-out

## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host from the network after confirming the presence of ransomware-related artifacts.
```
→ analyst-forensic-review

## analyst-forensic-review
<!-- Analyst forensic review -->
```manual target=analyst
Examine the file renames and ransom note creation on the isolated host. Identify the originating process and any related network activity. Confirm if data exfiltration occurred prior to encryption.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
If no malicious activity was found, document the hosts examined and the state of their vulnerabilities for follow-up patching.
```
→ end
