Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Pearl Sleet

Also known as: DEV-0215, LAWRENCIUM

Description

Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, media organizations in carrying out their cyber espionage activities.

AI Analysis

· 1 week ago

Executive Summary

Pearl Sleet (DEV-0215, LAWRENCIUM) is a North Korea-based cyber espionage group targeting defectors and media organizations. They have been active since at least 2012, focusing on intelligence gathering likely linked to political or internal security objectives.

Goals & Targeting

Pearl Sleet targets defectors and media organizations to gather intelligence that could be used for political manipulation or national security in North Korea. Their targeting strategy reflects a focus on sectors likely to hold sensitive information regarding the regime or its citizens.

Enhanced Description

Pearl Sleet is a nation-state activity group attributed to North Korea, operating since 2012. Their primary targets include defectors from North Korea and media organizations, suggesting a focus on cyber espionage. The group's activities aim to gather sensitive information, possibly for political purposes such as monitoring internal dissent or influencing external narratives about North Korea.

Key Capabilities

  • Spear phishing attacks
  • Malware development/deployment
  • Data exfiltration
  • C2 infrastructure management

MITRE ATT&CK Tactics

Reconnaissance
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

Software / Tooling

Custom malware
Spear phishing tools

Campaigns & Victims

Pearl Sleet has conducted long-term campaigns targeting specific individuals and organizations. Their operations suggest a focus on maintaining persistence and secrecy, aligning with typical nation-state espionage tactics.

IOC Patterns

  • Spear-phishing emails targeting defectors
  • Malware embedded in malicious attachments or links
  • C2 infrastructure communication patterns

Recommended Actions

  • Implement advanced email filtering solutions to detect spear-phishing attempts.
  • Monitor for unusual network activity indicative of persistent threats.
  • Conduct regular security training on recognizing phishing emails.
  • Segment networks and apply least privilege principles to mitigate lateral movement.

Suggested Tags

Nation-state
Cyber Espionage
North Korea
Media Organizations

Confidence Assessment

High confidence in the group's nation-state affiliation but limited specifics on TTPs beyond common espionage tactics. Gaps include exact tools and detailed attack patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state
Cyber Espionage
North Korea
Media Organizations

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.