Reconstructing the DPRK Cyber Ecosystem: Infrastructure Pivoting, Malware Lineage, and Operational Attribution - Cybersecurity Conference

Reconstructing the DPRK Cyber Ecosystem: Infrastructure Pivoting, Malware Lineage, and Operational Attribution

At first glance, they appeared independent—different lures, different malware, different victims, and different operational objectives. One targeted South Korean organization through strategic espionage. Another focused-on government and policy experts using document-based social engineering. The third abused U.S. tax-season themes to steal credentials and financial assets.

This presentation examines three recent investigations: Operation HanKook Phantom, an APT37 espionage campaign targeting South Korean organizations; Kimsuky’s continued use of document-based lures to compromise government and policy-related targets; and Stealerium-infostealer campaigns leveraging U.S. tax-season themes to harvest credentials and financial information. Through these case studies, we analyze the attackers’ infection chains, phishing strategies, malware deployment, persistence mechanisms, and operational tradecraft.

APT campaigns rarely evolve in isolation—they evolve as an ecosystem. Attendees will learn how reverse engineering, infrastructure correlation, phishing telemetry, ATT&CK mapping, and adversary tradecraft analysis can uncover hidden operational patterns across multiple DPRK campaigns.

Dixit Panchal

He is a Threat Researcher at NetProtector AV, where he is part of the Biz Secure Lab team. Previously, he worked as a Security Researcher at Quick Heal Technologies Ltd., contributing to the Seqrite Lab team.

His areas of expertise include threat hunting, malware research and analysis, APT analysis, and incident response. He specializes in investigating emerging cyber threats, analyzing sophisticated malware and attack techniques, and developing proactive strategies to identify, understand, and mitigate evolving security threats.

Vaibhav Billade

He is currently working as a Deputy Manager – Cyber Engineering at Deloitte, where he focuses on cybersecurity engineering, threat intelligence, and security research. Previously, he worked as a Senior Security Researcher at Quick Heal Technologies Ltd., contributing to the Seqrite Lab team.

His expertise spans threat hunting, malware analysis, reverse engineering, APT research, threat intelligence, and detection engineering. He focuses on identifying and analyzing emerging threats, investigating complex malware and attack techniques, developing effective security detections, and conducting IOC investigation, alert analysis, threat investigation, and incident response. He leverages threat intelligence and adversary insights to strengthen proactive threat detection and security operations.