Also known as: Silent Chollima, Stonefly, Onyx Sleet, DarkSeoul, TEMP.Firework, Black Banshee, Bureau 121, Lab 110, WICKED PANDA
Wassonite (also known by aliases Silent Chollima and Black Banshee) is linked to the North Korea‑based Lazarus Group and has repeatedly targeted high‑value industrial control environments across Asia since 2018. The gang's operations are primarily centered on information gathering, credential theft and data exfiltration rather than sabotage. Attackers first establish footholds through spear‑phishing or drive‑by compromises that deliver the DTrack RAT—an advanced remote access trojan capable of persisting via a custom WBService component and masquerading as legitimate utilities such as OllyDbg or 7‑Zip. Once inside, Wassonite employs Mimikatz to harvest domain credentials and uses the collected passwords for lateral movement across network shares. Its reconnaissance toolkit includes system discovery commands (ipconfig, netstat) and registry queries to gather host information, while exfiltration is performed by staging data into encrypted or password‑protected archives before transferring it through inbound channels like HTTP/S or SMB. The group also integrates a keylogging module that captures screen activity and keystrokes, further enriching the intelligence payload. Despite its stealthy posture, Wassonite avoids destructive actions; there are no documented incidents of plant sabotage or significant operational disruption. However, its continued use of sophisticated credential theft, persistence mechanisms, and data‑exfiltration techniques make it a persistent threat to critical infrastructure sectors such as nuclear energy, manufacturing, finance and maritime transport.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Wassonite is a North‑Korean espionage-focused APT that has been active since at least 2018, targeting industrial control sectors—including nuclear facilities—in India, South Korea and Japan. The group employs the DTrack RAT to gain remote footholds, steals credentials with Mimikatz, and exfiltrates data by staging it in password‑protected archives. While lacking known destructive capabilities, its toolset mirrors that of other Lazarus Group campaigns such as DarkSeoul.
Goals & Targeting
Wassonite's strategic objective is long‑term intelligence collection from assets that influence national security, economic stability and geopolitical leverage. The group prioritizes high‑value targets—including nuclear power facilities, manufacturing plants, financial services firms and critical infrastructure—primarily in India, South Korea, Japan, Iran, Russia and China. Their targeting approach blends social engineering with exploitative lateral movement to gain deep situational insight while maintaining a low profile to avoid detection. The APT appears motivated by state‑level espionage, seeking information that could inform political or economic advantage for its sponsoring nation rather than direct sabotage. Consequently, the focus remains on reconnaissance, data harvesting and covert exfiltration rather than active disruption.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since 2018, Wassonite has repeatedly infiltrated nuclear power facilities such as India’s Kudankulam plant and other industrial control environments in South Korea and Japan. The operational tempo has been sporadic but sustained, typically launching reconnaissance or credential‑stealing phases before staging exfiltration. Victims range from energy sector utilities to financial institutions and manufacturing plants; the group favors organizations with complex network architectures and multiple administrative domains to extend coverage. Key patterns include spear‑phishing lures themed around nuclear or industrial content, the use of a custom RAT that installs a hidden service for persistence, and exfiltration via encrypted archives transmitted over standard protocols (HTTPS, SMB). The group has not been observed deploying destructive payloads—their activities align more closely with intelligence gathering than sabotage. Notable operations identified include a 2020 incident at the Kudankulam Nuclear Power Plant in India involving DTrack deployment and credential harvesting; earlier analysis links similar toolsets to Lazarus Group campaigns such as DarkSeoul, indicating common operational staff or shared R&D capabilities.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
33
Techniques
34
Tools
0
Campaigns
6
IOCs
0
Observed Data
7
Tactics